PT-2026-57328 · Unknown · Openreplay

CVE-2026-55881

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenReplay versions 1.22.0 through 1.26.x
Description An issue exists where the getFirstMob() function returns 15-second presigned S3 download URLs for a session's DOM-replay recording based only on the session path parameter. The validateProjectAccess() function fails to verify if the session belongs to the project, checking only that the project belongs to the requester's tenant. This allows an authenticated low-privilege user to access the first 15 seconds of session-replay recording data from another tenant.
Recommendations Update to version 1.27.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55881
GHSA-W2X5-M7W5-479H

Affected Products

Openreplay