PT-2026-41030 · Crabbox · Crabbox

Published

2026-05-14

·

Updated

2026-05-14

·

CVE-2026-8629

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Crabbox versions prior to 0.12.0
Description Insufficient access control checks allow users with shared visibility-only access to escalate privileges. By sending POST requests to the endpoints "/v1/leases/:id/code/ticket", "/v1/leases/:id/webvnc/ticket", and "/v1/leases/:id/egress/ticket", attackers can obtain Code, WebVNC, and Egress agent tickets. This enables the impersonation of trusted lease-side bridges despite the user having only visibility permissions.
Recommendations Update to version 0.12.0 or later.

Exploit

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8629

Affected Products

Crabbox