Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jul 14, 2026
Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers
CVE-2026-56767
Description
Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execute other users' robots by bypassing ownership checks in API endpoints.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/getmaxun/maxun/commit/11db0257531f1c23dec94727793c9444ee2873cfmitrepatch
- www.vulncheck.com/advisories/maxun-cross-tenant-idor-in-storage-and-webhook-api-handlersmitrethird-party-advisory
- github.com/getmaxun/maxun/issues/1079mitretechnical-description
- github.com/getmaxun/maxun/pull/1088mitreissue-tracking
News mentions
0No linked articles in our index yet.