PT-2026-82223 · Midday · Midday
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Midday (affected versions not specified)
Description
An authorization flaw exists in the team management logic where the system fails to verify the user role during team deletion and updates. The delete procedure in the
apps/api/src/trpc/routers/team.ts file uses a team-access helper that grants access to any member regardless of their role, instead of restricting the action to the owner. This allows any invited user with the Member role to delete the entire team and all associated records. Furthermore, the deletion process triggers a cleanup job that utilizes stored bank-connection tokens against connected providers. The update procedure within the same router also lacks the necessary role verification.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Midday