IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6.
Metrics
Affected Vendors & Products
References
History
Mon, 04 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Authorization in IKUS Rdiffweb Allows Cross‑Tenant Access | |
| First Time appeared |
Ikus-soft
Ikus-soft rdiffweb |
|
| Weaknesses | CWE-285 | |
| Vendors & Products |
Ikus-soft
Ikus-soft rdiffweb |
Mon, 04 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-04T18:49:37.072Z
Reserved: 2025-12-12T00:00:00.000Z
Link: CVE-2025-67796
No data.
Status : Received
Published: 2026-05-04T20:16:16.260
Modified: 2026-05-04T20:16:16.260
Link: CVE-2025-67796
No data.
OpenCVE Enrichment
Updated: 2026-05-04T20:30:08Z