PT-2026-95501 · Convoy · Convoy

CVE-2026-81505

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Convoy versions prior to 26.6.8
Description An issue exists in the GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint where the system authorizes access to the project specified in the URL but fails to verify if the requested source actually belongs to that project. The Handler.GetSource function calls sources.Service.FindSourceByID(), which retrieves the source record using only the sourceID variable, ignoring the project authorization. Consequently, an authenticated user or a holder of a project-scoped API key can access any other tenant's source record by substituting the sourceID. This leads to the exposure of complete source records, including unredacted plaintext credentials for AMQP, Kafka, SQS, or Google PubSub brokers. This is a cross-tenant credential leak affecting only single-item source lookups, while the list endpoint remains correctly scoped.
Recommendations Update Convoy to version 26.6.8. As a temporary mitigation, restrict access to the GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint to trusted administrators only.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81505
GHSA-P5VG-V7MJ-F6Q4
GO-2026-6523

Affected Products

Convoy