CVE-2026-91774

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
4.3
MEDIUM

Description

Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to read full team records. Attackers can supply a known team identifier to retrieve sensitive team data including name, description, owner information, and settings without membership verification.

Published
September 15, 2026 2:16 AM
Last Modified
September 15, 2026 2:16 AM
Source
[email protected]

Weaknesses (CWE)

CWE-862

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.