PT-2026-41030 · Crabbox · Crabbox
Published
2026-05-14
·
Updated
2026-05-14
·
CVE-2026-8629
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Crabbox versions prior to 0.12.0
Description
Insufficient access control checks allow users with shared visibility-only access to escalate privileges. By sending POST requests to the endpoints "/v1/leases/:id/code/ticket", "/v1/leases/:id/webvnc/ticket", and "/v1/leases/:id/egress/ticket", attackers can obtain Code, WebVNC, and Egress agent tickets. This enables the impersonation of trusted lease-side bridges despite the user having only visibility permissions.
Recommendations
Update to version 0.12.0 or later.
Exploit
Fix
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crabbox