Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 13, 2026
OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint
CVE-2026-55881
Description
OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAccess checked only that the project belonged to the requester's tenant and did not verify that the session belonged to that project, allowing any authenticated low-privilege user to read another tenant's first 15 seconds of session-replay recording data. This issue is fixed in version 1.27.0.
Affected products
1- Range: 1.22.0 <= v < 1.27.0
Patches
Vulnerability mechanics
References
4- github.com/openreplay/openreplay/commit/ddd09117f644a309c7b040cda0a11ff9433e9e49mitrex_refsource_MISC
- github.com/openreplay/openreplay/pull/4692mitrex_refsource_MISC
- github.com/openreplay/openreplay/releases/tag/v1.27.0mitrex_refsource_MISC
- github.com/openreplay/openreplay/security/advisories/GHSA-w2x5-m7w5-479hmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.