Cross-Tenant Authorization Flaw in Daytona by DaytonA
CVE-2026-54324

6.5MEDIUM

Key Information:

Vendor

Daytonaio

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54324?

Daytona, an infrastructure runtime designed for AI-generated code execution and agent workflows, contains a cross-tenant authorization flaw in its notification WebSocket gateway. This issue allows authenticated users to inadvertently subscribe to and receive real-time notifications from other organizations, potentially leading to unauthorized access to sensitive events. The vulnerability has been addressed in version 0.185.0 and users are urged to upgrade to this version to ensure their environments are protected from such unauthorized access.

Affected Version(s)

daytona < 0.185.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.