← Volver al buscador de CVEs

CVE-2026-18640

Descripción

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org-s data store directory. The file written must have an extension of -.json.db- but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.

CVSS 7.1EPSS 0%Riesgo 0.71
Ver fuente
Publicación
2026-08-11 16:17:30
Última modificación
2026-08-11 18:17:21
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L