Authorization Bypass in Network-AI Affecting Multiple Versions
CVE-2026-64622

9.3CRITICAL

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-64622?

The affected versions of Network-AI fail to enforce critical authorization checks on several ApprovalInbox GET routes, allowing unauthorized users to access detailed approval requests. Specifically, routes such as GET /approvals/?status=all and GET /approvals/:id reveal sensitive information, including commands, paths, justifications, and risk levels. Additionally, responses are sent with a permissive Access-Control-Allow-Origin header, which can lead to cross-origin exposure of sensitive information across different domains. This vulnerability is an incomplete remedy for a prior issue, indicating ongoing security concerns.

Affected Version(s)

Network-AI 5.12.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sec-reex
.