CVE-2026-59097Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can supply an arbitrary project identifier to these endpoints, which bypass permission checks and apply the AllowAny default, to pre-empt project administrators from initializing due dates by creating records before they can do so themselves.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-02)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-27: 1Mentions · 2026-07-02: 2Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 1Technical Details · 2026-07-02: 201-2707-02
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-271
Patch1
2026-07-022
Disclosure2
Full discourse3 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical vulnerabilities in #dormakaba access manager #exos9300. #CVE-2025-59090 #CVE-2026-59097 #CVE-2026-59108 #CVE-2025-59103 CVSS: 9.3-9.2. See official advisories: https://www.dormakabagroup.com/en/security-advisories #Patch #Patch #Patch

    Post summary

    The tweet alerts about multiple critical CVEs affecting Dormakaba Exos 9300, provides CVSS scores, and points to official advisories for patches.

    00001237
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59097 Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by e… https://www.cve.org/CVERecord?id=CVE-2026-59097 ----- Traducción: CVE-2026-59097 Tai… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-59097, describing a missing authorization flaw allowing unauthenticated attackers to create default due‑date records in any project.

    0000044
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59097 Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by e… https://www.cve.org/CVERecord?id=CVE-2026-59097

    Post summary

    The text announces a missing authorization vulnerability in Taiga versions prior to 6.10.2, allowing unauthenticated remote attackers to create default due‑date records in any project.

    00000950
    57.7K followersView on X

Explore more