PT-2026-107380 · Candlepin · Candlepin

CVE-2026-106471

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Candlepin (affected versions not specified)
Description A flaw in the central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, rather than requiring access to every verified entity. A low-privilege authenticated attacker who can access the first referenced object can bypass authorization checks on subsequent objects. If target resource identifiers are known, this can lead to the unauthorized disclosure of consumer information and the unauthorized modification of entitlements and related subscription resources, potentially across different organizations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106471

Affected Products

Candlepin