Improper access control in Pivotal Concourse - #VU144318
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in the TSA worker management functionality when handling connections authenticated with a team-scoped worker private key. A remote privileged user can connect to TSA and land or retire team-scoped workers belonging to other teams to cause a denial of service.
This only affects team-scoped private keys.