PT-2026-98848 · Ail+1 · Ail Framework

·

CVE-2026-100177

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AIL Framework (affected versions not specified)
Description The crawler task creation API 'api add crawler task' contains an insufficient authorization check when a user provides a cookiejar UUID for a one-shot or scheduled crawler task. The system fails to validate organizational boundaries or the requesting user's role. Specifically, if the cookiejar access level is not 0, no access check is performed; if it is 0, the system only compares the owning user ID to the requesting user ID. An authenticated user with the ability to create crawler tasks who knows or guesses a valid cookiejar UUID from another organization can force the crawler to use that organization's stored cookies, such as session tokens and authentication credentials, leading to the exfiltration of session data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100177

Affected Products

Ail Framework