← Volver al buscador de CVEs

CVE-2026-55880

OpenReplay

Descripción

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id and project id, while dashboards.update_widget and dashboards.remove_widget filtered only on dashboard id and widget id, allowing any authenticated member to delete another user-s private session notes and remove or rewrite widgets on another user-s private dashboards.

CVSS 7.1EPSS 0.19499999999999998%Riesgo 0.72
Ver fuente
Publicación
2026-07-10 21:16:57
Versiones afectadas
<=1.27.0
Tipo
Aplicación web
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L