PT-2026-95501 · Convoy · Convoy
CVE-2026-81505
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Convoy versions prior to 26.6.8
Description
An issue exists in the
GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint where the system authorizes access to the project specified in the URL but fails to verify if the requested source actually belongs to that project. The Handler.GetSource function calls sources.Service.FindSourceByID(), which retrieves the source record using only the sourceID variable, ignoring the project authorization. Consequently, an authenticated user or a holder of a project-scoped API key can access any other tenant's source record by substituting the sourceID. This leads to the exposure of complete source records, including unredacted plaintext credentials for AMQP, Kafka, SQS, or Google PubSub brokers. This is a cross-tenant credential leak affecting only single-item source lookups, while the list endpoint remains correctly scoped.Recommendations
Update Convoy to version 26.6.8.
As a temporary mitigation, restrict access to the
GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint to trusted administrators only.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Convoy