Improper access control in Pivotal Concourse - #VU144317
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in the HeartbeatWorker endpoint when handling authenticated heartbeat requests to another team\'s worker. A remote user can send a crafted heartbeat request with invalid worker information to cause a denial of service.
The issue affects authenticated users even if they have no team membership.