Medium severity4.3NVD Advisory· Published Jun 27, 2024· Updated Jun 17, 2026
CVE-2024-6086
CVE-2024-6086
Description
In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The function checkAccess() is not implemented, allowing users with the lowest privileges, such as the 'Prompt Editor' role, to modify organization attributes without proper authorization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- huntr.com/bounties/9e83f63f-c5c1-422f-8010-95c353f0c643nvdExploitThird Party Advisory
- github.com/lunary-ai/lunary/commit/3451fcd7b9d95e9091d62c515752f39f2faa6e54nvd
News mentions
0No linked articles in our index yet.