CVE-2026-82287

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 20:20

Updated : 2026-08-31 19:17


NVD link : CVE-2026-82287

Mitre link : CVE-2026-82287

CVE.ORG link : CVE-2026-82287


JSON object : View

Products Affected

No product.

CWE
CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains