Access Control Vulnerability in Harness Infrastructure Provider
CVE-2026-92750
7.1HIGH
What is CVE-2026-92750?
A significant access control vulnerability exists in Harness version 3.3.0, where the read endpoint for infrastructure providers lacks proper access control validation. This flaw enables authenticated users to exploit the GET /api/v1/infraproviders endpoint, potentially disclosing sensitive provider configurations from unauthorized spaces. By manipulating space identifiers, attackers can access critical metadata, such as Docker endpoints, TLS certificate paths, and cloud project identifiers, posing a risk to data integrity and security.
Affected Version(s)
harness 0 <= 3.3.0
