๐Ÿ” CVE Alert

CVE-2026-108729

MEDIUM 5.9

Corteza through 2024.9.10 Unauthenticated Attachment Access via Compose Attachment Endpoints

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL kind segment to page, icon, or namespace. Attackers who know a private record or module attachment id can request the original or preview route without a token or signature to retrieve files across namespace and record permission boundaries.

CWE CWE-863
Vendor cortezaproject
Product corteza
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for cortezaproject corteza

Be the first to know when new medium vulnerabilities affecting cortezaproject corteza are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

cortezaproject / corteza
0 โ‰ค 2024.9.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/corteza-attachment-kind-confusion-unauth-read github.com: https://github.com/cortezaproject/corteza/blob/3835dfc4ac8bd89381753f09042ad147a4502576/server/compose/rest/attachment.go#L79-L122 github.com: https://github.com/cortezaproject/corteza/blob/3835dfc4ac8bd89381753f09042ad147a4502576/server/compose/service/attachment.go#L123-L142 github.com: https://github.com/cortezaproject/corteza/commit/3b68aa30c7261f729fcf8202f3eab9cf7d9168d3 github.com: https://github.com/cortezaproject/corteza vulncheck.com: https://www.vulncheck.com/advisories/corteza-through-2024.9.10-unauthenticated-attachment-access-via-compose-attachment-endpoints

Credits

HaiND from the Post and Telecommunication Institute of Technology