Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execute other users' robots by bypassing ownership checks in API endpoints.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Jun 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getmaxun
Getmaxun maxun |
|
| Vendors & Products |
Getmaxun
Getmaxun maxun |
Thu, 25 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execute other users' robots by bypassing ownership checks in API endpoints. | |
| Title | Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-25T20:28:18.697Z
Reserved: 2026-06-22T21:55:17.942Z
Link: CVE-2026-56767
Updated: 2026-06-25T20:27:17.737Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T22:00:12Z