CVE-2026-45226
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary
CVSS
7.1
High
EPSS
0.3%
p22
KEV
—
Exploit Today
6
0-100
Published: May 12, 2026 · Last modified: Jul 14, 2026 · CWE-863
0.3%EPSS · 30 days0.3%
2026-08-102026-09-06
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds pointing to victim workflow UUIDs to load and execute those workflows under attacker-controlled execution paths, exposing victim workflow outputs and triggering workflow nodes with unintended side effects.
- github.comhttps://github.com/heymrun/heym/commit/3ae3ef6a7d3609da0e910f9ed6b81e99a1661ac8
- github.comhttps://github.com/heymrun/heym/pull/93
- github.comhttps://github.com/heymrun/heym/releases/tag/v0.0.21
- www.vulncheck.comhttps://www.vulncheck.com/advisories/heym-authorization-bypass-in-workflow-execution
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-865448.1 HIG—
———knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.14hCVE-2026-864377.2 HIG—
———Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.15hCVE-2026-864987.7 HIG—
———In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission20hCVE-2026-864936.5 MED—
———In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards20hCVE-2026-864906.5 MED—
———In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint20hCVE-2026-864873.1 LOW—
———In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content20h