
🔒 CVE-2026-63178 (CVSS Score: 6.5): Onyx Curator-Scope IDOR Turns Group Membership Into a Backdoor Curators could rewrite membership of ANY group in the deployment, not just their own and inherit that group's documents in the process. 🔗 Read full blog: https://secnora.com/blog/cve-2026-63178-onyx-curator-scope-idor/
Post summary
The post announces the discovery of CVE‑2026‑63178, an IDOR flaw in Onyx Curator that allows unauthorized group membership changes, and provides basic technical details including the CVSS score.
