CVE-2026-85700

Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext authorization headers and third-party API credentials, then use them to directly access upstream APIs.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 15:17

Updated : 2026-09-04 15:17


NVD link : CVE-2026-85700

Mitre link : CVE-2026-85700

CVE.ORG link : CVE-2026-85700


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials