CVE-2024-6086

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/06/2024
Last modified:
15/10/2025

Description

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organization attributes without proper authorization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lunary:lunary:1.2.7:*:*:*:*:*:*:*