Lakefs · Lakefs · CVE-2026-66006
**Name of the Vulnerable Software and Affected Versions**
lakeFS versions prior to 1.83.0 commit 71a45ee
**Description**
An authentication bypass exists in the '/setup comm prefs' endpoint. This allows unauthenticated attackers to overwrite operator metadata, such as `email`, `name`, and `company`, after the setup process is complete. By sending a POST request to this endpoint, attackers can modify security update preferences, disable security communications, and trigger falsified telemetry events using a legitimate installation ID.
**Recommendations**
Update lakeFS to the version containing commit 71a45ee.
As a temporary mitigation, restrict access to the '/setup comm prefs' endpoint.