CVE-2026-54746
Last modified
CVE-2026-54746 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the bearer-token context in Dispatcher/UpsertWorkerLabels and Dispatcher/Unsubscribe. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the bearer-token context in Dispatcher/UpsertWorkerLabels and Dispatcher/Unsubscribe. An authenticated owner of any tenant who guesses another tenant's worker UUID can overwrite that worker's affinity labels or disconnect the worker from the dispatcher. This can cause cross-tenant integrity impact and denial of service on multi-tenant Hatchet Cloud or shared self-hosted deployments. Single-tenant deployments are not practically affected because the attacker and target tenant are the same. This issue is fixed in version 0.91.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| hatchet-dev | hatchet | >= 0.40.0, < 0.91.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54746?
How severe is CVE-2026-54746?
How do I fix CVE-2026-54746?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5474A vulnerability was found in NASA cFS up to 7.0.0. This affe…8.8
- CVE-2026-54740Lemmy is a link aggregator and forum for the fediverse. Prio…6.5
- CVE-2026-54741Lemmy is a link aggregator and forum for the fediverse. Prio…5.3
- CVE-2026-54742Lemmy is a link aggregator and forum for the fediverse. From…5.1
- CVE-2026-54743Lemmy is a link aggregator and forum for the fediverse. Prio…6.4
- CVE-2026-54745Kubeflow Pipelines enables users to build and deploy portabl…10
- CVE-2026-5475A vulnerability was determined in NASA cFS up to 7.0.0. This…5.5
- CVE-2026-54752NetBox Device Type Library is a collection of community-sour…9.6
- CVE-2026-54753Nx is a monorepo solution for TypeScript and polyglot codeba…5.9
- CVE-2026-54754Klever-Go is the Go implementation of the Klever blockchain …9.6
- CVE-2026-54755Klever-Go is the Go implementation of the Klever blockchain …9.6
- CVE-2026-54756Jodit Editor is a WYSIWYG editor with written in pure TypeSc…6.3
Are you affected by CVE-2026-54746?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
