Medium severity6.5NVD Advisory· Published Jul 17, 2026· Updated Jul 21, 2026
CVE-2026-63100
CVE-2026-63100
Description
Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsController, where the before_action ensure_admin filter is applied only to the clear_cache action. Attackers can read the operator's Synth API key rendered in plaintext via a form field value attribute, overwrite it with an attacker-controlled value, toggle public registration settings, and disable email confirmation requirements to disrupt the entire instance.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.