Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-8621

3 месяца назад

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a shared token to bypass authorization checks and access owner/org-scoped lease operations belonging to victim accounts.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g9m-rffv-h6wq

3 месяца назад

Crabbox: authentication bypass vulnerability that allows impersonation of others by spoofing identity headers

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-8621

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a shared token to bypass authorization checks and access owner/org-scoped lease operations belonging to victim accounts.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4g9m-rffv-h6wq

Crabbox: authentication bypass vulnerability that allows impersonation of others by spoofing identity headers

CVSS3: 8.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу