Role Modification and Deletion Vulnerability in Daytona by DaytonaAI
CVE-2026-54322
What is CVE-2026-54322?
Daytona, developed by DaytonaAI, is a secure infrastructure runtime designed for executing AI-generated code and managing agent workflows. Prior to version 0.185.0, the system had a significant vulnerability allowing an authenticated user who owns any organization to modify or delete roles belonging to different organizations. This occurred because the role update and delete endpoints did not properly verify that the roles belonged to the requesting organization; they only used the role's identifier. Consequently, this oversight could lead to unauthorized role permission changes, posing a risk to the security and integrity of organizational data. Users are strongly encouraged to upgrade to version 0.185.0 or later to mitigate this risk.
Affected Version(s)
daytona < 0.185.0
