A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configuration.
History

Wed, 22 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 22 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Apr 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configuration.
Title CVE-2026-6355
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-04-22T14:19:45.268Z

Reserved: 2026-04-15T13:48:22.716Z

Link: CVE-2026-6355

cve-icon Vulnrichment

Updated: 2026-04-22T14:18:32.851Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-22T14:17:06.627

Modified: 2026-04-22T21:23:52.620

Link: CVE-2026-6355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T19:30:24Z