VYPR
Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 13, 2026

OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint

CVE-2026-55881

Description

OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAccess checked only that the project belonged to the requester's tenant and did not verify that the session belonged to that project, allowing any authenticated low-privilege user to read another tenant's first 15 seconds of session-replay recording data. This issue is fixed in version 1.27.0.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.