Improper access control in Xray Audit - CVE-2026-96389

 

Improper access control in Xray Audit - CVE-2026-96389

Published: October 8, 2026


Vulnerability identifier: #VU154002
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-96389
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to the affected module does not sufficiently check entity access when rendering an entity through the display-mode example route. A remote attacker can bypass implemented security restrictions and view unpublished or otherwise access-restricted content.


Affected software

Xray Audit

How to mitigate CVE-2026-96389

Install updates from vendor's website.

Xray Audit - addressed in versions 1.6.3, 2.0.4, 3.1.1

External References

Related Security Bulletins