CVE-2026-45226
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary
CVSS
7.1
Alto
EPSS
0.3%
p22
KEV
—
Exploit Today
6
0-100
Publicado: 12 may 2026 · Última mod.: 14 jul 2026 · CWE-863
0.3%EPSS · 30 días0.3%
2026-08-102026-09-07
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds pointing to victim workflow UUIDs to load and execute those workflows under attacker-controlled execution paths, exposing victim workflow outputs and triggering workflow nodes with unintended side effects.
- github.comhttps://github.com/heymrun/heym/commit/3ae3ef6a7d3609da0e910f9ed6b81e99a1661ac8
- github.comhttps://github.com/heymrun/heym/pull/93
- github.comhttps://github.com/heymrun/heym/releases/tag/v0.0.21
- www.vulncheck.comhttps://www.vulncheck.com/advisories/heym-authorization-bypass-in-workflow-execution
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-865448.1 ALT—
——0knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.15hCVE-2026-864377.2 ALT—
——0Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.16hCVE-2026-864987.7 ALT—
——0In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission3hCVE-2026-864936.5 MED—
——0In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards3hCVE-2026-864906.5 MED—
——0In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint3hCVE-2026-864873.1 BAJ—
——0In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content3h