HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 20:20
Updated : 2026-08-28 22:16
NVD link : CVE-2026-82279
Mitre link : CVE-2026-82279
CVE.ORG link : CVE-2026-82279
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
