CVE-2026-90768
CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.
| CWE | CWE-862 |
| Vendor | kevoreilly |
| Product | capev2 |
| Published | Sep 13, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for kevoreilly capev2
Be the first to know when new high vulnerabilities affecting kevoreilly capev2 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
kevoreilly / CAPEv2
0 โค 471ee4bb422ec4aa0f1aa1089540a1ad0b7d84f0
References
github.com: https://github.com/kevoreilly/CAPEv2/issues/3162 github.com: https://github.com/kevoreilly/CAPEv2 github.com: https://github.com/kevoreilly/CAPEv2/blob/1255b18/web/apiv2/views.py vulncheck.com: https://www.vulncheck.com/advisories/capev2-through-commit-471ee4b-rest-api-task-endpoints-missing-ownership-check
Credits
๐ George Chen