Medium severity6.5NVD Advisory· Published Sep 16, 2026
CVE-2026-92765
CVE-2026-92765
Description
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=2.0.6
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.