Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user. | |
| Title | Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials | |
| Weaknesses | CWE-942 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T16:19:05.231Z
Reserved: 2026-08-28T11:12:53.034Z
Link: CVE-2026-82287
No data.
Status : Received
Published: 2026-08-28T20:20:20.243
Modified: 2026-08-28T20:20:20.243
Link: CVE-2026-82287
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:15:04Z
Weaknesses