Cross-Tenant Affinity Label Overwrite in Hatchet Platform
CVE-2026-54746
6.4MEDIUM
What is CVE-2026-54746?
The Hatchet platform, designed for orchestrating background tasks and durable workflows, has a vulnerability in its Dispatcher gRPC service that allows authenticated users to manipulate worker IDs across different tenants. Specifically, from version 0.40.0 to 0.91.1, an authenticated owner can exploit this flaw to overwrite affinity labels or disconnect workers associated with other tenants, potentially leading to cross-tenant integrity issues and denial of service in multi-tenant deployments. This vulnerability does not significantly impact single-tenant configurations as the attacker and target tenant are typically the same. The issue has been resolved in version 0.91.1.
Affected Version(s)
hatchet >= 0.40.0, < 0.91.1
