PT-2026-50181 · Daytona · Daytona

·

CVE-2026-54322

·

Published

2026-06-16

·

Updated

2026-07-30

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Daytona versions prior to 0.185.0
Description Organization role update and delete endpoints authorized the caller as an owner of the organization in the request path but mutated the target role using only its identifier without verifying the role belonged to that organization. This results in a cross-tenant broken access control (IDOR - Insecure Direct Object Reference), where an authenticated user owning any organization could modify permissions or delete a role belonging to a different organization if the role identifier is known. An attacker could overwrite a target role's name and permission set to escalate or strip privileges, delete the role, or observe the current permission set via the update response.
Recommendations Update to version 0.185.0.

Exploit

Fix

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54322
GHSA-QXVM-PCFM-QC39
GO-2026-5600
OPENSUSE-SU-2026:21483-1

Affected Products

Daytona