ZeroHour

CVE-2026-92765

niche

Broken object-level authorization in ArcherySec ≤ 2.0.6 leaks cross-tenant findings

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92765 is an organization-ownership validation flaw (CWE-639, broken object-level authorization) in the WebScanVulnList endpoint of ArcherySec, an open-source vulnerability assessment and management platform. An authenticated user can supply arbitrary scan identifiers belonging to a different organization, and the endpoint returns the results without checking tenant ownership. This lets the attacker read complete web vulnerability records from other tenants, including titles, severities, statuses, and analyst notes, though no write or availability impact is involved. Any multi-tenant deployment of ArcherySec up to and including version 2.0.6 is affected, with the greatest risk where low-privileged accounts exist across tenant boundaries or where the instance is internet-facing. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; the issue was assigned by the VulnCheck CNA.

What to do: Upgrade ArcherySec to the latest release (any version newer than 2.0.6) once a patched build is available, since the flaw affects everything through 2.0.6. In the meantime, restrict access to WebScanVulnList at the reverse proxy or API-gateway layer, minimize the number of authenticated accounts (especially low-privileged ones in multi-tenant setups), and review access logs for requests enumerating scan IDs outside the user's own organization. If the instance is internet-exposed, limit it to trusted networks or VPN access.

Affected
ArcherySec (open-source project) ArcherySecall versions through and including 2.0.6
Estimated exposure
nichelikely hundreds to a few thousand self-hosted instances (order of magnitude in the low thousands at most) — ArcherySec is a niche open-source vulnerability management tool typically self-hosted by security teams and service providers rather than a mass-market product, so the affected population is a small set of internal or multi-tenant…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.

Weakness
CWE-639
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.