IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Authorization Allows Cross‑Tenant Data Access in IKUS Rdiffweb |
Tue, 05 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Authorization in IKUS Rdiffweb Allows Cross‑Tenant Access | |
| Weaknesses | CWE-285 |
Tue, 05 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Mon, 04 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Authorization in IKUS Rdiffweb Allows Cross‑Tenant Access | |
| First Time appeared |
Ikus-soft
Ikus-soft rdiffweb |
|
| Weaknesses | CWE-285 | |
| Vendors & Products |
Ikus-soft
Ikus-soft rdiffweb |
Mon, 04 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-04T00:00:00.000Z
Updated: 2026-05-05T15:06:54.781Z
Reserved: 2025-12-12T00:00:00.000Z
Link: CVE-2025-67796
Updated: 2026-05-05T15:06:34.818Z
Status : Received
Published: 2026-05-04T20:16:16.260
Modified: 2026-05-05T16:16:10.420
Link: CVE-2025-67796
No data.