CVE-2026-92765
ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
| CWE | CWE-639 |
| Vendor | archerysec |
| Product | archerysec |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for archerysec archerysec
Be the first to know when new medium vulnerabilities affecting archerysec archerysec are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
archerysec / archerysec
0 โค 2.0.6
References
github.com: https://github.com/archerysec/archerysec/issues/676 github.com: https://github.com/archerysec/archerysec github.com: https://github.com/archerysec/archerysec/blob/v2.0.6/webscanners/views.py#L297-L313 vulncheck.com: https://www.vulncheck.com/advisories/archerysec-through-2.0.6-information-disclosure-via-webscanvulnlist
Credits
George Chen