No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 25 Jul 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Treeverse
Treeverse lakefs |
|
| Vendors & Products |
Treeverse
Treeverse lakefs |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID. | |
| Title | lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-25T10:30:05.605Z
Reserved: 2026-07-23T19:22:30.643Z
Link: CVE-2026-66006
Updated: 2026-07-24T15:30:48.191Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T22:45:17Z