Devguard · Devguard · CVE-2026-48089
**Name of the Vulnerable Software and Affected Versions**
DevGuard versions prior to 1.4.2
**Description**
On API instances with public assets, any authenticated user can perform unauthorized write operations, regardless of their organization, project, or asset membership. This allows attackers to create, update, reapply, and delete VEX rules, as well as manage dependency-vuln events (including accept, reject, and mitigate decisions), batch event creation, vulnerability synchronization, mitigation, license risk creation, external reference writes, artifact creation, and license refreshes. This issue impacts the integrity of the vulnerability data for public assets, potentially allowing attackers to silence vulnerabilities or provide misleading justifications, which affects downstream consumers relying on `vex.json` and `sbom.json` endpoints.
**Recommendations**
Update to version 1.4.2.
As a temporary workaround, change the visibility of affected assets from public to private in the asset settings to restore correct authorization on write endpoints.