PT-2026-83170 · Hatchet · Hatchet

CVE-2026-54746

·

Published

2026-08-28

·

Updated

2026-09-08

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Hatchet versions 0.40.0 through 0.91.0
Description The Dispatcher gRPC service fails to verify if a request's worker ID belongs to the tenant identified by the bearer-token context. This occurs within the Dispatcher/UpsertWorkerLabels and Dispatcher/Unsubscribe endpoints. An authenticated owner of any tenant who can guess another tenant's worker UUID can overwrite that worker's affinity labels or disconnect the worker from the dispatcher. This leads to cross-tenant integrity impact and denial of service in multi-tenant Hatchet Cloud or shared self-hosted deployments. Single-tenant deployments are not practically affected.
Recommendations Update to version 0.91.1.

Exploit

Fix

DoS

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54746
GHSA-8X7X-83CF-C3PG
GO-2026-6309
OPENSUSE-SU-2026:21812-1

Affected Products

Hatchet