← Back to CVE search

CVE-2026-18640

Description

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org-s data store directory. The file written must have an extension of -.json.db- but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.

CVSS 7.1EPSS 0%Risk 0.71
View source
Published
2026-08-11 16:17:30
Last modified
2026-08-11 18:17:21
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L