CVE-2026-8629
Last modified
CVE-2026-8629 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-8629?
How severe is CVE-2026-8629?
How do I fix CVE-2026-8629?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86283MISP's UiBeta theme collection view (app/View/Themed/UiBeta/…7.1
- CVE-2026-86284A security vulnerability has been detected in jaychouchannel…5.3
- CVE-2026-86285A vulnerability was detected in BookStack up to 26.05.2. Aff…4.3
- CVE-2026-86287Net::IP::LPM versions before 1.12 for Perl accept malformed …7.5
- CVE-2026-86288A vulnerability has been found in ModelCloud GPTQModel up to…6.3
- CVE-2026-86289A vulnerability was found in Ollama up to 0.31.1. This issue…4.3
- CVE-2026-86290A weakness has been identified in SourceCodester Online Voti…7.3
- CVE-2026-86291A security vulnerability has been detected in itsourcecode S…6.3
- CVE-2026-86292A vulnerability was detected in SourceCodester Simple Traffi…7.3
- CVE-2026-86293A flaw has been found in SourceCodester Simple Traffic Offen…6.5
- CVE-2026-86294A vulnerability has been found in SourceCodester Simple Traf…4.3
- CVE-2026-86295A vulnerability was found in D-Link DIR-895L A1_102b07. This…8.3
Are you affected by CVE-2026-8629?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
