PT-2026-71718 · Rainbond · Rainbond

·

CVE-2026-72741

·

Published

2026-08-13

·

Updated

2026-08-18

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Rainbond versions prior to 6.9.8
Description Broken access control exists in the CheckToken() function. Authenticated attackers can access unauthorized enterprise resources by substituting another enterprise's tenant name within URL paths. By using any valid API token, an attacker can bypass enterprise ID verification to access or modify services, plugins, environment variables, and certificates belonging to another enterprise.
Recommendations Update to version 6.9.8 or later. As a temporary workaround, restrict access to the CheckToken() function to minimize the risk of exploitation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72741

Affected Products

Rainbond