A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-23 21:17
Updated : 2026-09-11 19:17
NVD link : CVE-2026-15630
Mitre link : CVE-2026-15630
CVE.ORG link : CVE-2026-15630
JSON object : View
Products Affected
No product.
