๐Ÿ” CVE Alert

CVE-2026-90768

HIGH 8.1

CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.

CWE CWE-862
Vendor kevoreilly
Product capev2
Published Sep 13, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for kevoreilly capev2

Be the first to know when new high vulnerabilities affecting kevoreilly capev2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

kevoreilly / CAPEv2
0 โ‰ค 471ee4bb422ec4aa0f1aa1089540a1ad0b7d84f0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kevoreilly/CAPEv2/issues/3162 github.com: https://github.com/kevoreilly/CAPEv2 github.com: https://github.com/kevoreilly/CAPEv2/blob/1255b18/web/apiv2/views.py vulncheck.com: https://www.vulncheck.com/advisories/capev2-through-commit-471ee4b-rest-api-task-endpoints-missing-ownership-check

Credits

๐Ÿ” George Chen