CVE-2026-8629

Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.
Configurations

No configuration.

History

14 May 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 20:17

Updated : 2026-05-15 14:11


NVD link : CVE-2026-8629

Mitre link : CVE-2026-8629

CVE.ORG link : CVE-2026-8629


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key