Authorization Flaw in Corteza Affects Private Attachments Accessibility
CVE-2026-108729
8.2HIGH
What is CVE-2026-108729?
Corteza versions up to 2024.9.10 exhibit an authorization flaw within the compose attachment endpoints, permitting unauthenticated attackers to download private attachments. By manipulating the URL kind segment to 'page', 'icon', or 'namespace', attackers who possess knowledge of a private record or module attachment ID can access the original or preview route. This exploitation allows unauthorized retrieval of files by bypassing namespace and record permission boundaries, posing significant data exposure risks.
Affected Version(s)
corteza 0 <= 2024.9.10
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
