PT-2026-96169 · Unknown · Deepstream
CVE-2026-63116
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
deepstream version 10.1.0
Description
An issue exists where the
src/services/permission/valve/rules-map.ts file omits RECORD ACTION.PATCH MULTI from the RULES MAP. When an authenticated user performs a PATCH MULTI record operation while the permission.type is set to config, the getRulesForMessage() function returns a null rule specification. Consequently, the ConfigPermission.canPerformAction() function treats this missing specification as an unconditional allowance instead of applying RULE TYPES.WRITE. This allows any authenticated user to modify arbitrary protected records, corrupt application state, or cause service disruption. Deployments using the default permission type none are not additionally affected.Recommendations
Update deepstream to version 10.1.1.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deepstream