PT-2026-48812 · Devguard · Devguard

·

CVE-2026-48089

·

Published

2026-06-11

·

Updated

2026-07-30

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions DevGuard versions prior to 1.4.2
Description On API instances with public assets, any authenticated user can perform unauthorized write operations, regardless of their organization, project, or asset membership. This allows attackers to create, update, reapply, and delete VEX rules, as well as manage dependency-vuln events (including accept, reject, and mitigate decisions), batch event creation, vulnerability synchronization, mitigation, license risk creation, external reference writes, artifact creation, and license refreshes. This issue impacts the integrity of the vulnerability data for public assets, potentially allowing attackers to silence vulnerabilities or provide misleading justifications, which affects downstream consumers relying on vex.json and sbom.json endpoints.
Recommendations Update to version 1.4.2. As a temporary workaround, change the visibility of affected assets from public to private in the asset settings to restore correct authorization on write endpoints.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48089
GHSA-6P54-FW2F-Q7GF
GO-2026-5183
OPENSUSE-SU-2026:21483-1

Affected Products

Devguard