Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints. | |
| Title | HyperDX Team Management Operations Missing Role-Based Access Control | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T16:18:59.661Z
Reserved: 2026-08-28T11:12:50.244Z
Link: CVE-2026-82279
No data.
Status : Received
Published: 2026-08-28T20:20:19.067
Modified: 2026-08-28T20:20:19.067
Link: CVE-2026-82279
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization