CVE-2026-12593Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. Precondition for successful exploitation was a preexisting internal user (with more privileges than the attacker), the attacker knowing its login name and the attacker being able to authenticate to the Dashboard via OAuth/OIDC. The attacker would then have had to forge a token creation API request on behalf of the other user and could have authenticated and finalized the token creation with their own OAuth/OIDC credentials. In the worst case, this would mean an attacker could have become Dashboard Administrator and been able to perform all administrative actions if the preexisting internal user had administrative privileges. In combination with a separate weakness, this could have further led to code execution on the host system running the Dashboard with the privileges of the OS-User running the Dashboard server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-09: 3Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 307-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-12593 The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token… https://www.cve.org/CVERecord?id=CVE-2026-12593

    Post summary

    The text discloses CVE-2026-12593, detailing that an undocumented API endpoint accepts token creation requests without proper HTTP validation.

    01011678
    57.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Broken auth in undocumented Dashboard token creation API (CVE-2026-12593) An internal, undocumented Dashboard API endpoint used to create user API tokens fails to enforce authorization when creating a token on behalf of another user. The root cause is broken access control / missing authorization checks (IDOR-style privilege boundary bypass) in the token-issuance workflow. An authenticated attacker via OAuth/OIDC who knows a higher-privileged internal user’s login can submit a forged token creation request for that target user and then finalize the flow using their own credentials. Successful exploitation can escalate privileges up to Dashboard Administrator, and when chained with an additional weakness may enable code execution on the Dashboard host under the Dashboard server OS user. 👉 Affected: Dashboard (versions not specified; internal token-creation API endpoint) | Upgrade to Vendor fix once released (No fix yet — treat as suspicious)

    Post summary

    An undocumented Dashboard token‑creation API suffers from IDOR‑style broken auth, allowing privilege escalation up to Administrator and potential code execution, but no PoC or active exploitation has been reported.

    1000099
    246 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12593 The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token… https://www.cve.org/CVERecord?id=CVE-2026-12593 ----- Traducción: CVE-2026-12593 La … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑12593, noting a missing HTTP request enforcement in an internal Dashboard API that could allow unauthorized API token creation.

    0000035
    91 followersView on X

Explore more