CVE-2026-82279
Last modified
CVE-2026-82279 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints..
Description
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| hyperdxio | hyperdx | <= 1.10.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-82279?
How severe is CVE-2026-82279?
How do I fix CVE-2026-82279?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82273Mastra through 1.63.0 contains an authentication bypass vuln…6.5
- CVE-2026-82274Twenty through 2.35.0 contains an open redirect vulnerabilit…4.7
- CVE-2026-82275Qwen-Agent through 0.0.34 contains a path traversal vulnerab…7.5
- CVE-2026-82276StarRocks through 4.0.13 contains an authentication bypass v…5.3
- CVE-2026-82277Argo Rollouts dashboard through 1.10.0 binds to all interfac…9.8
- CVE-2026-82278BISHENG before 2.6.0 contains a remote code execution vulner…8.8
- CVE-2026-8228A security vulnerability has been detected in Wavlink NU516U…8.8
- CVE-2026-82280Quivr through 0.0.322 fails to validate ownership in prompt …7.1
- CVE-2026-82281Kotaemon through 0.12.0 fails to properly validate conversat…7.4
- CVE-2026-82282Atlantis through 0.47.1 fails to authenticate the /github-ap…8
- CVE-2026-82283VoltAgent through 2.1.20 fails to validate conversation owne…8.1
- CVE-2026-82284Quivr versions through 0.0.322 fail to validate chat ownersh…8.1
Are you affected by CVE-2026-82279?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
