Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sec-Reex

#28049of 54,901
9.3Total CVSS
Vulnerabilities · 1
PT-2026-61582
9.3
2026-07-20
Unknown · Network-Ai · CVE-2026-64622
**Name of the Vulnerable Software and Affected Versions** Network-AI versions 5.12.2 through 5.13.3 **Description** The software fails to apply the configured authorization check `checkAuth/secret` to the ApprovalInbox GET read routes. This allows unauthenticated actors to access sensitive approval request details, including action/target shell-command strings, file paths, justifications, and risk levels. The affected API endpoints are '/approvals/?status=all', '/approvals/:id', '/approvals/stats', and '/approvals/sse'. Additionally, responses include a hardcoded Access-Control-Allow-Origin: * header, which enables cross-origin disclosure from any website visited by the operator. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.