Authorization Bypass in Network-AI Affecting Multiple Versions
CVE-2026-64622
9.3CRITICAL
What is CVE-2026-64622?
The affected versions of Network-AI fail to enforce critical authorization checks on several ApprovalInbox GET routes, allowing unauthorized users to access detailed approval requests. Specifically, routes such as GET /approvals/?status=all and GET /approvals/:id reveal sensitive information, including commands, paths, justifications, and risk levels. Additionally, responses are sent with a permissive Access-Control-Allow-Origin header, which can lead to cross-origin exposure of sensitive information across different domains. This vulnerability is an incomplete remedy for a prior issue, indicating ongoing security concerns.
Affected Version(s)
Network-AI 5.12.2
