CVE Watchtower

← Back to CVE List

CVE-2026-90768NVD

Description

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.
Severity Level
HIGH (8.1)
Published Date
13/09/2026
Last Modified
14/09/2026
Exploitation Status
????
EPSS Score
0.24% (percentile 15.8%)

CVSS Base Metrics

CVSS v3 (3.1)
HIGH 8.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4 (4.0)
HIGH 8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Weaknesses (CWE)

CWE-862 - Missing Authorization

Affected & Patched Versions

ProductAffected VersionsPatched Version
kevoreilly CAPEv20 - <= 471ee4bb422ec4aa0f1aa1089540a1ad0b7d84f0N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.