
Abdullah Kareem@CyberKareem
Disclosure
New one on the board: CVE-2026-59979. Cross-tenant IDOR in Yosemite-Crew (OSS vet practice mgmt). Their security-fix PR added RBAC to the create routes but forgot the update/delete ones so any low-priv user (even a patient account) could edit or delete another clinic's data. https://t.co/4NobkLLi91
Post summary
A new CVE (2026‑59979) exposes a cross‑tenant IDOR in Yosemite‑Crew, letting low‑priv users edit or delete other clinic data; a partial fix applies RBAC to create routes but not to update/delete operations.
0000063
236 followersView on X
