Sceawere

Vulnerability Detail

CVE-2026-108729UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Corteza Unauthenticated Attachment Access Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
4h ago
Vendor
cortezaproject
Product
corteza
Attack Type
Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL kind segment to page, icon, or namespace. Attackers who know a private record or module attachment id can request the original or preview route without a token or signature to retrieve files across namespace and record permission boundaries.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-10-11T13:17:16.750Z",
  "pubdate": "2026-10-11T13:17:16.750Z",
  "executiveSummary": "Corteza versions through 2024.9.10 are susceptible to an incorrect authorization vulnerability within the compose attachment endpoints.\nThe flaw allows unauthenticated remote attackers to bypass access control mechanisms and retrieve sensitive, private attachments.\nBy manipulating the URL 'kind' segment, an attacker can bypass token and signature verification processes designed to restrict file access based on namespace and record permissions.\nThis vulnerability constitutes a critical information disclosure risk, as it effectively nullifies existing permission boundaries, allowing unauthorized exfiltration of proprietary or restricted data.\nExploitation requires no authentication, making it accessible to any actor capable of reaching the target instance.\nThe vulnerability originates from a failure to strictly validate authorization requirements for specific file retrieval routes, exposing system-wide attachments to unauthorized requests.",
  "technicalDetails": "The vulnerability resides in the compose attachment handling logic of the Corteza platform. The system implements a routing mechanism that processes file retrieval requests based on a 'kind' parameter within the URL path. It has been identified that the application fails to enforce session-based authorization or signature validation when the 'kind' segment is set to specific values, namely 'page', 'icon', or 'namespace'.\nIn a secure configuration, any attempt to access a file—whether the original file or a preview variant—should undergo an authorization check to verify that the requesting user possesses the necessary permissions to access the corresponding record or module attachment ID. Due to this flaw, the application incorrectly assumes that these specific 'kind' segments do not require authentication or explicit permission scoping.\nThe attack flow proceeds as follows: 1) The attacker identifies or enumerates a target private attachment ID (e.g., a UUID associated with a record or module file). 2) The attacker constructs a malicious GET request to the compose attachment endpoint, incorporating the target ID and setting the 'kind' segment to 'page', 'icon', or 'namespace'. 3) The application’s routing layer incorrectly categorizes these requests as exempt from security checks. 4) The back-end retrieves the requested file from the storage layer without verifying the identity or authorization context of the requester. 5) The sensitive file is returned directly to the unauthenticated attacker.\nBecause the vulnerability bypasses the intended permission boundaries, an attacker can retrieve files across all namespaces and records, effectively ignoring any administrative restrictions or access control lists (ACLs) applied to the platform’s attachments. This allows for the bulk exfiltration of data, including potential PII, configuration files, or sensitive business documents, simply by iterating through known or guessed attachment IDs. The lack of requirement for a valid token or cryptographic signature significantly lowers the barrier to entry, as the attacker only needs network reachability to the Corteza installation and the target resource identifiers.\nThis issue affects all Corteza installations up to and including version 2024.9.10, emphasizing a fundamental flaw in the handling of attachment request metadata that assumes the 'kind' parameter serves as a proxy for authorization rather than a descriptor for content type."
}
CVE-2026-108729: Corteza Unauthenticated Attachment Access Vulnerability (MEDIUM Severity, CVSS: 5.9) | Sceawere