Role Modification and Deletion Vulnerability in Daytona by DaytonaAI
CVE-2026-54322

7.7HIGH

Key Information:

Vendor

Daytonaio

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54322?

Daytona, developed by DaytonaAI, is a secure infrastructure runtime designed for executing AI-generated code and managing agent workflows. Prior to version 0.185.0, the system had a significant vulnerability allowing an authenticated user who owns any organization to modify or delete roles belonging to different organizations. This occurred because the role update and delete endpoints did not properly verify that the roles belonged to the requesting organization; they only used the role's identifier. Consequently, this oversight could lead to unauthorized role permission changes, posing a risk to the security and integrity of organizational data. Users are strongly encouraged to upgrade to version 0.185.0 or later to mitigate this risk.

Affected Version(s)

daytona < 0.185.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.