PT-2026-60793 · Git+1 · Maybe

·

CVE-2026-63100

·

Published

2026-07-17

·

Updated

2026-07-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Maybe versions prior to 0.6.0
Description Authenticated users with low-privilege member roles can access and modify global hosting settings. This occurs because the ensure admin filter is only applied to the clear cache action within the Settings::HostingsController, leaving the show and update actions unprotected. An attacker can exploit this to read the operator's Synth API key in plaintext, overwrite it with a custom value, toggle public registration settings, and disable email confirmation requirements.
Recommendations Update to version 0.6.0 or later. Restrict access to the Settings::HostingsController to prevent unauthorized users from accessing the show and update actions.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63100

Affected Products

Maybe