Beveiligingsadvies

CVE-2026-8621

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-14 18:46:43
Laatst bijgewerkt 2026-07-14 22:03:58
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a shared token to bypass authorization checks and access owner/org-scoped lease operations belonging to victim accounts.