Access Control Vulnerability in Harness Infrastructure Provider
CVE-2026-92750

7.1HIGH

Key Information:

Vendor

Harness

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92750?

A significant access control vulnerability exists in Harness version 3.3.0, where the read endpoint for infrastructure providers lacks proper access control validation. This flaw enables authenticated users to exploit the GET /api/v1/infraproviders endpoint, potentially disclosing sensitive provider configurations from unauthorized spaces. By manipulating space identifiers, attackers can access critical metadata, such as Docker endpoints, TLS certificate paths, and cloud project identifiers, posing a risk to data integrity and security.

Affected Version(s)

harness 0 <= 3.3.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.