PT-2026-57328 · Unknown · Openreplay
CVE-2026-55881
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenReplay versions 1.22.0 through 1.26.x
Description
An issue exists where the
getFirstMob() function returns 15-second presigned S3 download URLs for a session's DOM-replay recording based only on the session path parameter. The validateProjectAccess() function fails to verify if the session belongs to the project, checking only that the project belongs to the requester's tenant. This allows an authenticated low-privilege user to access the first 15 seconds of session-replay recording data from another tenant.Recommendations
Update to version 1.27.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openreplay