Improper Authorization Affecting github.com/l3montree-dev/devguard/middlewares package, versions <1.4.2


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.36% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOML3MONTREEDEVDEVGUARDMIDDLEWARES-17675643
  • published29 Jun 2026
  • disclosed19 Jun 2026
  • creditUnknown

Introduced: 19 Jun 2026

CVE-2026-48089  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade github.com/l3montree-dev/devguard/middlewares to version 1.4.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authorization in the authorization process for public assets. An attacker can perform unauthorized actions such as creating, updating, reapplying, and deleting VEX rules, as well as making changes to vulnerability-triage endpoints, dependency-vuln events, batch events, vulnerability synchronization, mitigation, license risk creation, external reference writes, and artifact creation by using a valid account on the instance, even without membership in the victim organization, project, or asset. This is only exploitable if the targeted asset is configured as public.

Workaround

This vulnerability can be mitigated by changing the asset visibility from public to private in the asset settings, which restores correct authorization on all write endpoints for that asset.

CVSS Base Scores

version 4.0
version 3.1