CVE-2026-92765
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
16/09/2026
Última modificación:
24/09/2026
Descripción
*** Pendiente de traducción *** ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
Impacto
Puntuación base 4.0
7.10
Gravedad 4.0
ALTA
Puntuación base 3.x
6.50
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/archerysec/archerysec
- https://github.com/archerysec/archerysec/blob/v2.0.6/webscanners/views.py#L297-L313
- https://github.com/archerysec/archerysec/issues/676
- https://www.vulncheck.com/advisories/archerysec-through-2.0.6-information-disclosure-via-webscanvulnlist
- https://github.com/archerysec/archerysec/issues/676


