Authorization Bypass Vulnerability in Candlepin by Red Hat
CVE-2026-106471
8.1HIGH
What is CVE-2026-106471?
A significant flaw exists in Candlepin where the central authorization filter improperly grants access when any one of several @Verify-annotated parameters is available. This vulnerability permits a low-privilege authenticated adversary to bypass necessary authorization checks on subsequent resource objects. If an attacker is capable of accessing the first referenced object, they may exploit this flaw to gain unauthorized access to sensitive consumer data, as well as modify entitlements and related subscription resources across multiple organizations, leading to potential data breaches and misuse of subscription features.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Xanlar Agamalizade for reporting this issue.