๐Ÿ” CVE Alert

CVE-2026-82267

MEDIUM 5.4

Komodo Resource Identifier Disclosure and Audit Log Pollution Before Permission Check

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess resource names to obtain internal identifiers and insert fraudulent audit log entries misrepresenting privileged operations.

CWE CWE-862
Vendor moghtech
Product komodo
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for moghtech komodo

Be the first to know when new medium vulnerabilities affecting moghtech komodo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

moghtech / komodo
0 โ‰ค 2.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moghtech/komodo/issues/1455 github.com: https://github.com/moghtech/komodo github.com: https://github.com/moghtech/komodo/blob/cc1c5aa5dabb738e843c47f5e87fc040648c2bb7/bin/core/src/helpers/update.rs github.com: https://github.com/moghtech/komodo/blob/cc1c5aa5dabb738e843c47f5e87fc040648c2bb7/bin/core/src/api/execute/mod.rs vulncheck.com: https://www.vulncheck.com/advisories/komodo-resource-identifier-disclosure-and-audit-log-pollution-before-permission-check

Credits

๐Ÿ” George Chen