Authorization Flaw in Corteza Affects Private Attachments Accessibility
CVE-2026-108729

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108729?

Corteza versions up to 2024.9.10 exhibit an authorization flaw within the compose attachment endpoints, permitting unauthenticated attackers to download private attachments. By manipulating the URL kind segment to 'page', 'icon', or 'namespace', attackers who possess knowledge of a private record or module attachment ID can access the original or preview route. This exploitation allows unauthorized retrieval of files by bypassing namespace and record permission boundaries, posing significant data exposure risks.

Affected Version(s)

corteza 0 <= 2024.9.10

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.