PT-2026-96169 · Unknown · Deepstream

CVE-2026-63116

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions deepstream version 10.1.0
Description An issue exists where the src/services/permission/valve/rules-map.ts file omits RECORD ACTION.PATCH MULTI from the RULES MAP. When an authenticated user performs a PATCH MULTI record operation while the permission.type is set to config, the getRulesForMessage() function returns a null rule specification. Consequently, the ConfigPermission.canPerformAction() function treats this missing specification as an unconditional allowance instead of applying RULE TYPES.WRITE. This allows any authenticated user to modify arbitrary protected records, corrupt application state, or cause service disruption. Deployments using the default permission type none are not additionally affected.
Recommendations Update deepstream to version 10.1.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63116
GHSA-89VX-JH4Q-VG3W

Affected Products

Deepstream