CVE-2026-81505
Last modified
CVE-2026-81505 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID matches the authorized project.
Description
Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID matches the authorized project. An authenticated user or project-scoped API key holder can substitute another tenant's Source identifier and receive that Source's complete record, including unredacted AMQP, Kafka, SQS, or Google PubSub credentials. The list endpoint remains project-scoped; the single-item Source lookup is affected. This issue is fixed in version 26.6.8.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| frain-dev | convoy | < 26.6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81505?
How severe is CVE-2026-81505?
How do I fix CVE-2026-81505?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81481Dell OpenManage Server Administrator, versions prior to 11.1…7.5
- CVE-2026-81485A security vulnerability has been detected in danielpopamd l…5.3
- CVE-2026-81486A vulnerability was detected in bsmi021 mcp-file-context-ser…5.3
- CVE-2026-8149A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS b…5.1
- CVE-2026-81490A database user able to create a view in a namespace that Mo…7.7
- CVE-2026-81491A flaw has been found in boxpositron with-context-mcp up to …7.3
- CVE-2026-8151The Simple Membership MailChimp Integration WordPress plugin…5.4
- CVE-2026-81515Steeltoe is an open source project that provides a collectio…7.5
- CVE-2026-81516Steeltoe is an open source project that provides a collectio…7.5
- CVE-2026-81517An unauthenticated party able to reach the port of a MongoDB…7.5
- CVE-2026-81518When mongosqld is configured with a client certificate autho…7.5
- CVE-2026-8152Unblu Spark contains an open redirect vulnerability that can…9.3
Are you affected by CVE-2026-81505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
