Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kevoreilly
Kevoreilly capev2 |
|
| Vendors & Products |
Kevoreilly
Kevoreilly capev2 |
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification. | |
| Title | CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:39.835Z
Reserved: 2026-09-13T10:14:52.108Z
Link: CVE-2026-90768
No data.
Status : Received
Published: 2026-09-13T11:17:01.113
Modified: 2026-09-13T11:17:01.113
Link: CVE-2026-90768
No data.
OpenCVE Enrichment
Updated: 2026-09-13T19:54:35Z