CVE-2026-90768 PUBLISHED

CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check

Assigner: VulnCheck
Reserved: 13.09.2026 Published: 13.09.2026 Updated: 13.09.2026

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor kevoreilly
Product CAPEv2
Versions Default: unaffected
  • affected from 0 to 471ee4bb422ec4aa0f1aa1089540a1ad0b7d84f0 (incl.)

Credits

  • George Chen reporter

References

Problem Types

  • Missing Authorization CWE