Daytona · Daytona · CVE-2026-54321
**Name of the Vulnerable Software and Affected Versions**
Daytona versions 0.101.0 through 0.183.0
**Description**
Sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change. This occurs because a cached visibility state was not invalidated when the sandbox visibility changed, allowing the preview proxy to continue serving unauthenticated requests to ordinary preview ports for a bounded period. This issue only affects sandboxes that were previously public and then set to private. Terminal, toolbox, and recording-dashboard ports are not affected as they always require authentication. The issue does not involve cross-tenant access, privilege escalation, or remote code execution.
**Recommendations**
Update to version 0.184.0.