Medium severity5.9NVD Advisory· Published Oct 11, 2026
CVE-2026-108729
CVE-2026-108729
Description
Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL kind segment to page, icon, or namespace. Attackers who know a private record or module attachment id can request the original or preview route without a token or signature to retrieve files across namespace and record permission boundaries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/cortezaproject/corteza/blob/3835dfc4ac8bd89381753f09042ad147a4502576/server/compose/rest/attachment.gonvd
- github.com/cortezaproject/corteza/blob/3835dfc4ac8bd89381753f09042ad147a4502576/server/compose/service/attachment.gonvd
- github.com/cortezaproject/corteza/commit/3b68aa30c7261f729fcf8202f3eab9cf7d9168d3nvd
- hackmd.io/@haind03/corteza-attachment-kind-confusion-unauth-readnvd
- www.vulncheck.com/advisories/corteza-through-2024.9.10-unauthenticated-attachment-access-via-compose-attachment-endpointsnvd
News mentions
0No linked articles in our index yet.