CyberRota Analysis
AI-GeneratedThe Codefresh platform contains a vulnerability that allows authenticated users to exploit an API endpoint to gain elevated Admin permissions. This could lead to unauthorized access and control over the platform, potentially compromising sensitive data and system integrity. Organizations using Codefresh should prioritize addressing this issue to mitigate the risk of privilege escalation attacks.
CVE
CVE-2026-12878
Severity
HIGH
CVSS
8.8
EPSS
0.40%
Original NVD Description
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
Related CVEs
Other vulnerabilities affecting the same vendor(s)