PT-2026-81484 · Airbyte · Airbyte-Platform

·

CVE-2026-80049

·

Published

2026-08-25

·

Updated

2026-08-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airbyte Platform (affected versions not specified)
Description An issue exists where the platform determines the workspace for authorization decisions based on a field supplied by the caller. The AuthorizationServerHandler copies recognized identifiers from the raw JSON request body into X-Airbyte-* headers, and the AuthenticationHeaderResolver.resolveWorkspace() function prioritizes the X-Airbyte-Workspace-Id header over resource-derived headers. Because the extractor reads the request body instead of the endpoint schema, a caller can specify a workspaceId to pass permission checks while the handler operates on a different resource identifier. Since the system does not verify if the resource belongs to the authorized workspace, a member of any workspace can read configurations, trigger or cancel syncs, and delete connections, sources, and destinations belonging to workspaces they are not authorized to access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80049

Affected Products

Airbyte-Platform