PT-2026-96822 · Novu · Novu
CVE-2026-75517
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Novu versions prior to 3.18.0
Description
Novu provides an API for sending notifications through multiple channels. Certain integration mutation use cases fail to consistently enforce the
environmentId when looking up an integration by integrationId and organizationId. This allows a caller with access to one environment within an organization to target an integration identifier from another environment to delete the integration, modify credentials, change the primary provider, or trigger auto-configuration. This issue affects both environment API keys and dashboard sessions. While version 3.18.0 enforces the environment boundary for environment-scoped API-key authentication, it does not fully resolve the issue for dashboard sessions.Recommendations
Update to a version later than 3.18.0.
As a temporary mitigation, restrict access to the following API endpoints: 'remove-integration', 'update-integration', 'auto-configure-integration', and 'set-integration-as-primary'.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novu