← Retour à la recherche de CVE

CVE-2026-18640

Description

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org-s data store directory. The file written must have an extension of -.json.db- but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.

CVSS 7.1EPSS 0%Risque 0.71
Voir la source
Publication
2026-08-11 16:17:30
Dernière modification
2026-08-11 18:17:21
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L