HIGHVulnerability

CVE-2026-90768

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.

Properties

severity
HIGH
score
8.1
cve_id
CVE-2026-90768
signal_observed_at
2026-09-23T22:45:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
published_at
2026-09-13T11:17:01.113
last_modified
2026-09-23T17:17:47.457

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90768 — Ninja Signal Threat Intelligence | Ninja Signal