CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kevoreilly
Kevoreilly capev2 |
|
| Vendors & Products |
Kevoreilly
Kevoreilly capev2 |
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification. | |
| Title | CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:39.835Z
Reserved: 2026-09-13T10:14:52.108Z
Link: CVE-2026-90768
No data.
Status : Received
Published: 2026-09-13T11:17:01.113
Modified: 2026-09-13T11:17:01.113
Link: CVE-2026-90768
No data.
OpenCVE Enrichment
Updated: 2026-09-13T19:54:35Z
Weaknesses