Security Advisory

CVE-2026-88939

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-10 15:28:53
Last updated 2026-09-11 11:07:59
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.