CVE-2026-56355
Description
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
Root cause
"Savane through 3.17 uses untrusted data as part of authorization decisions."
Attack vector
An attacker can exploit this vulnerability by supplying untrusted data that is used in authorization decisions, potentially bypassing access controls. The advisory does not detail the exact network path or payload shape, but the exploit was demonstrated by Hacktron researchers against the live Savannah platform [ref_id=1]. The preconditions for exploitation are not fully specified in the available information.
Affected code
The advisory does not specify which functions or files are at fault; it only identifies the product as GNU Savannah Administration Savane through version 3.17. The vulnerability is described as using untrusted data as part of authorization, but no specific code paths are named in the bundle.
What the fix does
The Free Software Foundation, GNU, and volunteer staff patched all reported vulnerabilities along with additional security issues submitted during the review [ref_id=1]. The patch details are not included in the bundle, so the specific code changes are unknown. The advisory states that no evidence of sensitive data access or supply chain compromise was found after the fixes were applied.
Preconditions
- inputThe attacker must be able to supply untrusted data that is consumed by the authorization logic in Savane.
- networkThe attacker must have network access to the GNU Savannah service.
Generated on Jun 21, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
6- cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.phpmitre
- cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.phpmitre
- news.ycombinator.com/itemmitre
- www.fsf.org/news/statement-regarding-gnu-savannah-security-reportsmitre
- www.hacktron.aimitre
- www.mallory.ai/stories/019ee445-bdd4-7775-93b5-a8faaf5c2eb7mitre
News mentions
0No linked articles in our index yet.