CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-23 21:17

Updated : 2026-09-11 19:17


NVD link : CVE-2026-15630

Mitre link : CVE-2026-15630

CVE.ORG link : CVE-2026-15630


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-863

Incorrect Authorization