API Vulnerability in Novu Notification Platform
CVE-2026-75517

6.5MEDIUM

Key Information:

Vendor

Novuhq

Vendor
CVE Published:
22 September 2026

What is CVE-2026-75517?

The Novu Notification Platform, a service designed for efficient notification handling, has a vulnerability that compromises the API's integrity. Versions prior to 3.18.0 allow an assailant with access to one organizational environment to interact with different environment identifiers without adequate controls. Such actions include unauthorized deletion of integrations, alteration of integration credentials, and manipulation of the primary provider settings. Although version 3.18.0 includes partial mitigations by enforcing environment boundaries through API-key authentication, the issue persists for dashboard session interactions, necessitating further action for complete remediation.

Affected Version(s)

api-service < 3.18.0

novu < 3.18.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.