Back to overview

CVE-2026-66006

MEDIUM Exploitation: PoC
5.3
CVSS 3.1
Description
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID.

Metadata

CVE ID
CVE-2026-66006
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-23 19:22 UTC
Published
2026-07-24 14:57 UTC
Last updated
2026-07-24 15:30 UTC
Primary CWE
CWE-306
Missing Authentication for Critical Function
Vendor / Product
treeverse / lakeFS
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
treeverse lakeFS 0 ≤ 1.83.0, 71a45eeb1639d146d34b8effd7e86d077160ed7c
Weakness (CWE)
CWESourceDescription
CWE-306 cna Missing Authentication for Critical Function
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Back to overview