PT-2026-76835 · Unknown · Onyx Enterprise Edition
CVE-2026-63178
·
Published
2026-08-17
·
Updated
2026-08-25
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Onyx Enterprise Edition versions prior to 4.3.0
Description
In the Enterprise Edition of the Onyx AI platform, the endpoints 'PATCH /manage/admin/user-group/{user group id}' and 'POST /manage/admin/user-group/{user group id}/add-users' call the functions
update user group() and add users to user group() without enforcing the validate curator can modify group check. This allows a user with curator privileges to add accounts to arbitrary groups, potentially gaining unauthorized document access via get acl for user() and the OpenSearch access control list filter.Recommendations
Update Onyx Enterprise Edition to version 4.3.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onyx Enterprise Edition