CVE-2026-12593
Last modified
CVE-2026-12593 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. Precondition for successful exploitation was a preexisting internal user (with more privileges than the attacker), the attacker knowing its login name and the attacker being able to authenticate to the Dashboard via OAuth/OIDC. The attacker would then have had to forge a token creation API request on behalf of the other user and could have authenticated and finalized the token creation with their own OAuth/OIDC credentials. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. Precondition for successful exploitation was a preexisting internal user (with more privileges than the attacker), the attacker knowing its login name and the attacker being able to authenticate to the Dashboard via OAuth/OIDC. The attacker would then have had to forge a token creation API request on behalf of the other user and could have authenticated and finalized the token creation with their own OAuth/OIDC credentials. In the worst case, this would mean an attacker could have become Dashboard Administrator and been able to perform all administrative actions if the preexisting internal user had administrative privileges. In combination with a separate weakness, this could have further led to code execution on the host system running the Dashboard with the privileges of the OS-User running the Dashboard server.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Qt | Axivion | >= 7.8.5, <= 7.8.12; >= 7.9.0, < 7.9.13; >= 7.10.0, < 7.10.11; >= 7.11.0, < 7.11.7; >= 7.12.0, < 7.12.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-12593?
How severe is CVE-2026-12593?
How do I fix CVE-2026-12593?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12584The Payment Gateway for Redsys & WooCommerce Lite WordPress …7.5
- CVE-2026-12585The Abandoned Cart Lite for WooCommerce WordPress plugin bef…8.1
- CVE-2026-12586The Lenxel WP WordPress theme through 1.0.31 does not perfor…8.1
- CVE-2026-12588An attacker with access to an HX 10.0.0 and previous versio…6
- CVE-2026-12590Impact: In body-parser versions prior to 1.20.6 (1.x line) a…5.9
- CVE-2026-12592The SlimStat Analytics WordPress plugin before 5.5.0 does no…7.5
- CVE-2026-12595The LoginPress Pro plugin for WordPress is vulnerable to Aut…8.1
- CVE-2026-12597The LoginPress Pro plugin for WordPress is vulnerable to Aut…8.1
- CVE-2026-12598The LoginPress Pro plugin for WordPress is vulnerable to aut…8.1
- CVE-2026-1260Invalid memory access in Sentencepiece versions less than 0.…7.8
- CVE-2026-12602Incorrect default permissions in ArubaSign, affecting versio…8.8
- CVE-2026-12605In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSR…9.6
Are you affected by CVE-2026-12593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
