6.9

CVE-2026-66006

Exploit

lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LakefsLakefs Version <= 1.83.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.24
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
disclosure@vulncheck.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://github.com/treeverse/lakeFS/issues/10465
Exploit
Issue Tracking
https://github.com/treeverse/lakeFS/pull/10499
Patch
Issue Tracking
https://github.com/treeverse/lakeFS/commit/71a45eeb1639d146d34b8effd7e86d077160ed7c
Patch
https://www.vulncheck.com/advisories/lakefs-unauthenticated-operator-metadata-overwrite-via-setup-comm-prefs
Patch
Third Party Advisory