PT-2026-96822 · Novu · Novu

CVE-2026-75517

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Novu versions prior to 3.18.0
Description Novu provides an API for sending notifications through multiple channels. Certain integration mutation use cases fail to consistently enforce the environmentId when looking up an integration by integrationId and organizationId. This allows a caller with access to one environment within an organization to target an integration identifier from another environment to delete the integration, modify credentials, change the primary provider, or trigger auto-configuration. This issue affects both environment API keys and dashboard sessions. While version 3.18.0 enforces the environment boundary for environment-scoped API-key authentication, it does not fully resolve the issue for dashboard sessions.
Recommendations Update to a version later than 3.18.0. As a temporary mitigation, restrict access to the following API endpoints: 'remove-integration', 'update-integration', 'auto-configure-integration', and 'set-integration-as-primary'.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75517
GHSA-JH6R-HJHP-WH2H

Affected Products

Novu