Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfwv-5762-mwrm

Опубликовано: 23 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.4

Описание

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.

EPSS

Процентиль: 17%
0.00053
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
16 дней назад

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.

EPSS

Процентиль: 17%
0.00053
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-639