SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12878

HIGH · CVSS 8.8 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Codefresh platform contains a vulnerability that allows authenticated users to exploit an API endpoint to gain elevated Admin permissions. This could lead to unauthorized access and control over the platform, potentially compromising sensitive data and system integrity. Organizations using Codefresh should prioritize addressing this issue to mitigate the risk of privilege escalation attacks.

CVE
CVE-2026-12878
Severity
HIGH
CVSS
8.8
EPSS
0.40%

Original NVD Description

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)