Authorization Flaw in Debusine by Freexian Team
CVE-2026-11852
6.5MEDIUM
What is CVE-2026-11852?
Debusine, a solution designed for building, distributing, and maintaining Debian-based distributions, is susceptible to an authorization flaw. This vulnerability arises because endpoints that handle the creation and deletion of relationships between artifacts do not enforce any permissions checks beyond mere visibility of the artifacts. Consequently, unauthorized users may manipulate or delete artifacts, leading to potential security breaches in systems relying on Debusine.
Affected Version(s)
debusine 0.2.0 < 0.14.6