Beveiligingsadvies

CVE-2026-88939

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-10 15:28:53
Laatst bijgewerkt 2026-09-11 11:07:59
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.