Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fxc-8v96-j5f3

Опубликовано: 04 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.9

Описание

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

EPSS

Процентиль: 22%
0.00297
Низкий

9.9 Critical

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
3 месяца назад

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

EPSS

Процентиль: 22%
0.00297
Низкий

9.9 Critical

CVSS4

Дефекты

CWE-639