Access Control Flaw in Deck Config API Affects Product by Vendor
CVE-2026-77170
4.3MEDIUM
What is CVE-2026-77170?
The Deck config API has a critical access control vulnerability that permits authenticated users to modify board-scoped configuration keys for any arbitrary board ID. This occurs without proper validation of the user's ownership or permission to manage the specified board, potentially exposing sensitive configurations and leading to unauthorized changes.
Affected Version(s)
Deck 1.16.0 <= 1.18.0