๐Ÿ” CVE Alert

CVE-2026-48089

UNKNOWN 0.0

DevGuard has improper authorization on public assets

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public assets, any authenticated user โ€” including users from a different organization with no membership or role in the affected org/project โ€” can create, update, reapply, and delete VEX rules on those public assets. The same flaw affects the other vulnerability-triage write endpoints exposed under a public asset, including VEX rule create / update / reapply / delete; dependency-vuln event creation (accept / reject / mitigate decisions), batch event creation, vuln sync, and mitigation; license risk creation; external reference writes; and/or artifact creation and license refresh. The attacker needs a valid account on the instance, but no membership in the victim organization, project, or asset is required. Version `v1.4.2`contains a patch. As a workaround, make affected assets non-public. In the asset settings, switch visibility from public to private. This removes the public-read exemption in the access-control middleware and restores correct authorization on all write endpoints for that asset. Downstream consumers that previously relied on the public `vex.json` / `sbom.json` endpoints will need to be granted explicit access or must receive an exported file version until the patched release is deployed.

CWE CWE-285 CWE-863
Vendor l3montree-dev
Product devguard
Published Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for l3montree-dev devguard

Be the first to know when new unknown vulnerabilities affecting l3montree-dev devguard are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

l3montree-dev / devguard
< 1.4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/l3montree-dev/devguard/security/advisories/GHSA-6p54-fw2f-q7gf github.com: https://github.com/l3montree-dev/devguard/commit/1be88ec1309a5dc0566e35a23bdc4ea3ecd11417