ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
References
Configurations
No configuration.
History
17 Sep 2026, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/archerysec/archerysec/issues/676 - |
16 Sep 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 21:17
Updated : 2026-09-17 16:18
NVD link : CVE-2026-92765
Mitre link : CVE-2026-92765
CVE.ORG link : CVE-2026-92765
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
