CVE-2026-75517
Last modified
CVE-2026-75517 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary look up an integration by integrationId and organizationId without consistently enforcing environmentId. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary look up an integration by integrationId and organizationId without consistently enforcing environmentId. A caller with access to one environment in an organization can target an integration identifier from another environment and delete the integration, modify its credentials, change the primary provider, or trigger auto-configuration. The repository advisory defines both environment API keys and dashboard sessions as affected. The 3.18.0 change enforces the environment boundary only for environment-scoped API-key authentication, while its tests intentionally retain cross-environment dashboard-session behavior, so it does not completely remediate the advisory-defined scope. Version 3.18.0 is a partial fix attempt, and the dashboard-session behavior requires curator resolution.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| novuhq | novu | < 3.18.0 |
| @novu | api-service | < 3.18.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-75517?
How severe is CVE-2026-75517?
How do I fix CVE-2026-75517?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7551HKUDS OpenHarness contains a remote code execution vulnerabi…8.8
- CVE-2026-75510Novu provides an API for sending notifications through multi…5.1
- CVE-2026-75511Novu provides an API for sending notifications through multi…5.3
- CVE-2026-75513Marten is a .NET Transactional Document DB and Event Store o…9.1
- CVE-2026-75514BunkerWeb is an open-source, next-generation Web Application…5.9
- CVE-2026-75516The RabbitMQ Java client library allows Java and JVM-based a…8.7
- CVE-2026-7552The Geo Mashup plugin for WordPress is vulnerable to authori…5.3
- CVE-2026-75523Steeltoe is an open source project that provides a collectio…5.9
- CVE-2026-75526django CMS is an easy-to-use and developer-friendly enterpri…4.4
- CVE-2026-75528The Broken Link Checker plugin for WordPress is vulnerable t…7.2
- CVE-2026-75529Pandora is affected by a stored cross-site scripting vulnera…6.9
- CVE-2026-7553A vulnerability was found in code-projects Gym Management Sy…4.7
Are you affected by CVE-2026-75517?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
