PT-2026-53669 · Hasura+1 · Hasura+1

·

CVE-2026-57951

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mythic versions prior to 3.4.0.60
Description A broken Hasura permission filter exists on the payload build step table. This issue involves an always-satisfied or condition that bypasses operation-scoped access controls. Consequently, authenticated operators and spectators can query the payload build step table to read the step stdout, step stderr, step name, and step description variables across all operations on the server.
Recommendations Update to version 3.4.0.60 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57951

Affected Products

Hasura
Mythic