Sceawere
Vulnerability Detail
CVE-2026-108727UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
EdgeEver Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- tianma-if
- Product
- EdgeEver
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
EdgeEver through 1.108.0 contains a missing authorization vulnerability in the Hono API memo-template routes that allows holders of scoped API tokens to bypass token scope restrictions because template handlers never call requireScopes. Attackers with a token lacking write:memos can save a template and invoke POST /api/v1/templates/:id/use to create memos, and list, modify, or delete templates in the token owner's workspace.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:16.440Z",
"pubdate": "2026-10-11T13:17:16.440Z",
"executiveSummary": "EdgeEver through version 1.108.0 is susceptible to a missing authorization vulnerability within its Hono API memo-template route handlers. The flaw originates from the failure to implement mandatory scope validation for sensitive operations.\nSpecifically, the application fails to invoke the requireScopes function during template management procedures, allowing actors possessing restricted scoped API tokens to circumvent established security boundaries.\nBy leveraging an API token that lacks the 'write:memos' privilege, an unauthorized actor can perform privileged actions including the creation, modification, and deletion of templates within a target workspace. Furthermore, the attacker can exploit the 'POST /api/v1/templates/:id/use' endpoint to instantiate memos, effectively escalating their functional capabilities beyond the intended scope of their issued credentials.\nThis vulnerability presents a significant risk to data integrity and access control, as it enables unauthorized workspace manipulation despite restricted token issuance. The exploitation of this flaw does not require elevated privileges beyond the possession of a standard scoped API token, facilitating potential unauthorized data generation and management within the affected environment.",
"technicalDetails": "The root cause of this security defect is an improper authorization check within the application's backend architecture, specifically residing in the Hono API framework implementation for memo-template routes. The application relies on a granular scoping mechanism designed to restrict token utility; however, the logic within the template handler components fails to invoke the requireScopes function, which serves as the primary enforcement mechanism for validating requested operations against token permissions.\nAffected versions include all iterations of EdgeEver up to and including 1.108.0. The vulnerable component is identified within the template management logic of the Hono API interface, where security constraints are bypassed by design due to the omission of authorization middleware.\nThe exploitation flow begins when an attacker acquires a scoped API token that possesses limited permissions—specifically, one lacking the 'write:memos' capability. Under normal operating conditions, the system should reject any request attempting to perform unauthorized write operations or template lifecycle management with such a token. Due to the missing authorization check, the application processes the incoming request without validating the token's scope claims.\nAn attacker can exploit this by interacting directly with the API routes. For instance, by executing a request to the 'POST /api/v1/templates/:id/use' endpoint, the attacker instructs the backend to instantiate a memo based on a template. Because the template handlers lack the 'requireScopes' validation, the system executes this operation regardless of the token's initial restrictions. This lack of enforcement extends across the full lifecycle of template management, permitting the unauthorized listing, modification, and deletion of templates within the context of the token owner’s workspace.\nThe post-exploitation impact is notable as it permits unauthorized state changes. An attacker can manipulate the workspace environment, potentially leading to the injection of unwanted data or the deletion of legitimate configuration templates. Since the application fails to verify if the token is permitted to 'write:memos', the integrity of the workspace is compromised, allowing for a broader range of malicious actions than those originally authorized for the token holder. The lack of network segmentation or secondary authorization checks means that once the API call is received by the Hono framework, the malicious instruction is executed with the context of the authenticated user, bypassing the intended security policy."
}