Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hyperdxio
Hyperdxio hyperdx |
|
| Vendors & Products |
Hyperdxio
Hyperdxio hyperdx |
Fri, 28 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints. | |
| Title | HyperDX Team Management Operations Missing Role-Based Access Control | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T20:25:37.335Z
Reserved: 2026-08-28T11:12:50.244Z
Link: CVE-2026-82279
Updated: 2026-08-28T20:25:16.522Z
Status : Received
Published: 2026-08-28T20:20:19.067
Modified: 2026-08-28T22:16:56.410
Link: CVE-2026-82279
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:30:17Z