Authorization Flaw in Debusine by Freexian Team
CVE-2026-11852

6.5MEDIUM

Key Information:

Vendor

Debian

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-11852?

Debusine, a solution designed for building, distributing, and maintaining Debian-based distributions, is susceptible to an authorization flaw. This vulnerability arises because endpoints that handle the creation and deletion of relationships between artifacts do not enforce any permissions checks beyond mere visibility of the artifacts. Consequently, unauthorized users may manipulate or delete artifacts, leading to potential security breaches in systems relying on Debusine.

Affected Version(s)

debusine 0.2.0 < 0.14.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.