CVE-2026-92765
nicheBroken object-level authorization in ArcherySec ≤ 2.0.6 leaks cross-tenant findings
CVE-2026-92765 is an organization-ownership validation flaw (CWE-639, broken object-level authorization) in the WebScanVulnList endpoint of ArcherySec, an open-source vulnerability assessment and management platform. An authenticated user can supply arbitrary scan identifiers belonging to a different organization, and the endpoint returns the results without checking tenant ownership. This lets the attacker read complete web vulnerability records from other tenants, including titles, severities, statuses, and analyst notes, though no write or availability impact is involved. Any multi-tenant deployment of ArcherySec up to and including version 2.0.6 is affected, with the greatest risk where low-privileged accounts exist across tenant boundaries or where the instance is internet-facing. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; the issue was assigned by the VulnCheck CNA.
What to do: Upgrade ArcherySec to the latest release (any version newer than 2.0.6) once a patched build is available, since the flaw affects everything through 2.0.6. In the meantime, restrict access to WebScanVulnList at the reverse proxy or API-gateway layer, minimize the number of authenticated accounts (especially low-privileged ones in multi-tenant setups), and review access logs for requests enumerating scan IDs outside the user's own organization. If the instance is internet-exposed, limit it to trusted networks or VPN access.
| ArcherySec (open-source project) ArcherySec | all versions through and including 2.0.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.