Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55880

Опубликовано: 10 июл. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id and project id, while dashboards.update_widget and dashboards.remove_widget filtered only on dashboard id and widget id, allowing any authenticated member to delete another user's private session notes and remove or rewrite widgets on another user's private dashboards.

EPSS

Процентиль: 27%
0.00338
Низкий

7.1 High

CVSS3

Дефекты

CWE-639

EPSS

Процентиль: 27%
0.00338
Низкий

7.1 High

CVSS3

Дефекты

CWE-639