CVE-2026-69119
Last modified
CVE-2026-69119 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying ownership or access rights to the target project, enabling attackers with any valid GitHub token to invoke bare KV-store operations such as projects.Fetch and project.Delete against any project ID to achieve cross-tenant project takeover.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying ownership or access rights to the target project, enabling attackers with any valid GitHub token to invoke bare KV-store operations such as projects.Fetch and project.Delete against any project ID to achieve cross-tenant project takeover.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Taubyte | tau | <= 1.1.10 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-69119?
How severe is CVE-2026-69119?
How do I fix CVE-2026-69119?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69113Cap v0.3.1 contains a broken access control vulnerability in…5.4
- CVE-2026-69114Spacebar Server before commit 8d126f4 contains a cross-chann…6.5
- CVE-2026-69115OpenIM Server v3.8.3 contains a missing authorization vulner…6.5
- CVE-2026-69116FlyEnv before 4.18.0 fails to sanitize HTML from markdown re…6.1
- CVE-2026-69117NetBox 4.5.8 contains an ORM injection vulnerability that al…6.5
- CVE-2026-69118Cachet through 2.4.1 contains a server-side template injecti…8.8
- CVE-2026-6912Improperly controlled modification of dynamically-determined…8.8
- CVE-2026-69123Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-69124Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-69125Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-69127Kirby is an open-source content management system. Prior to …6.9
- CVE-2026-69129KubePi is a Kubernetes multi-cluster management panel. In ve…5.8
Are you affected by CVE-2026-69119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
