← Retour à la recherche de CVE

CVE-2026-55880

OpenReplay

Description

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id and project id, while dashboards.update_widget and dashboards.remove_widget filtered only on dashboard id and widget id, allowing any authenticated member to delete another user-s private session notes and remove or rewrite widgets on another user-s private dashboards.

CVSS 7.1EPSS 0.19499999999999998%Risque 0.72
Voir la source
Publication
2026-07-10 21:16:57
Versions concernées
<=1.27.0
Type
Application web
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L