PT-2026-33380 · Zrok · Zrok

Published

2026-04-16

·

Updated

2026-04-18

·

CVE-2026-40304

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions zrok versions prior to 2.0.1
Description A logical error exists in the ownership guard of the unaccess handler within the controller/unaccess.go file. When a frontend record has the environment id variable set to NULL, which identifies admin-created global frontends, the verification condition short-circuits to false. This allows the deletion process to proceed without ownership verification. A non-admin user possessing a global frontend token can use the 'DELETE /api/v2/unaccess' endpoint with any of their own environment IDs to permanently delete the global frontend, resulting in the disruption of all public shares routed through it.
Recommendations Update to version 2.0.1.

Fix

Incorrect Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-40304
GHSA-3JPJ-V3XR-5H6G

Affected Products

Zrok