Authentication Bypass Vulnerability in lakeFS by Treeverse
CVE-2026-66006
Key Information:
Badges
What is CVE-2026-66006?
The lakeFS product by Treeverse contains an authentication bypass vulnerability located at the /setup_comm_prefs endpoint. This flaw allows unauthenticated attackers to overwrite critical operator metadata, including sensitive information like email, name, and company details, after the setup phase is complete. By leveraging this vulnerability, attackers can send POST requests to alter security update preferences, disable vital security communications, and even initiate deceptive telemetry events using the genuine installation ID. This presents significant risks to the integrity and security of the system, necessitating immediate attention and remediation.
Affected Version(s)
lakeFS 0 <= 1.83.0
lakeFS 71a45eeb1639d146d34b8effd7e86d077160ed7c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
