← Zurück zur CVE-Suche

CVE-2026-75338

disconf

Beschreibung

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center.

CVSS 9.8EPSS 0.326%Risiko 1.01
Quelle öffnen
Veröffentlicht
2026-08-26 23:17:18
Betroffene Versionen
==2.6.36
Typ
Webanwendung
Zuletzt geändert
2026-08-27 17:19:57
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H