Missing Authorization Vulnerability in EdgeEver by Tianma
CVE-2026-108727

5.3MEDIUM

Key Information:

Vendor

Tianma-if

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108727?

The EdgeEver platform, specifically versions up to 1.108.0, is impacted by a missing authorization vulnerability within the Hono API's memo-template routes. This flaw enables users with scoped API tokens to bypass token scope restrictions due to insufficient checking of permissions in template handlers. An attacker possessing a token without necessary write permissions can inadvertently save templates and use the POST /api/v1/templates/:id/use endpoint to create memos, as well as manipulate the templates within the token owner's workspace. The lack of robust scope verification poses serious security risks to user data and API integrity.

Affected Version(s)

EdgeEver 0 <= 1.108.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.