CVE-2026-72741
Last modified
CVE-2026-72741 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| goodrain | rainbond | <= 6.9.7 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-72741?
How severe is CVE-2026-72741?
How do I fix CVE-2026-72741?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72735Dokploy is a free, self-hostable Platform as a Service (PaaS…9.9
- CVE-2026-72736Dokploy is a free, self-hostable Platform as a Service (PaaS…9.9
- CVE-2026-72737Dokploy is a free, self-hostable Platform as a Service (PaaS…9.6
- CVE-2026-72738Dokploy is a free, self-hostable Platform as a Service (PaaS…9.9
- CVE-2026-72739Dokploy is a free, self-hostable Platform as a Service (PaaS…6.5
- CVE-2026-72740Dokploy is a free, self-hostable Platform as a Service (PaaS…9.9
- CVE-2026-72742DSPy 3.3.0b1 contains a file exfiltration vulnerability in t…8.6
- CVE-2026-72743SQLBot through 1.10.0, fixed in commit c3f40a5, contains a s…5.4
- CVE-2026-72744Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21…6.2
- CVE-2026-72745Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-72746Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-72747AVideo fails to sanitize the phone field during user registr…7.2
Are you affected by CVE-2026-72741?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
