8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execute other users' robots by bypassing ownership checks in API endpoints.
AI Analysis
Cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers
Basic Information
ID
CVE-2026-56767
Source
VulnCheck
Published
Jun 25, 2026 at 18:03
Affected Product
Vendor
getmaxun
Product
maxun
Version
0.0.42
Affected Versions
getmaxun maxun 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
getmaxun
Product
maxun
Version
0.0.42