PT-2026-33380 · Zrok · Zrok

CVE-2026-40304

·

Published

2026-04-16

·

Updated

2026-07-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions zrok versions prior to 2.0.1
Description A logical error exists in the ownership guard of the unaccess handler within the controller/unaccess.go file. When a frontend record has the environment id variable set to NULL, which identifies admin-created global frontends, the verification condition short-circuits to false. This allows the deletion process to proceed without ownership verification. A non-admin user possessing a global frontend token can use the 'DELETE /api/v2/unaccess' endpoint with any of their own environment IDs to permanently delete the global frontend, resulting in the disruption of all public shares routed through it.
Recommendations Update to version 2.0.1.

Exploit

Fix

Incorrect Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40304
GHSA-3JPJ-V3XR-5H6G
GO-2026-5090
OPENSUSE-SU-2026:21483-1

Affected Products

Zrok