AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-68754

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A repository publisher lacking delete permissions can potentially alter the content of protected packages under certain conditions, leading to unauthorized modifications. This vulnerability poses a risk to the integrity of package management systems, making it crucial for organizations that rely on such repositories to prioritize mitigation efforts. Users and administrators of affected package management solutions should assess their configurations and apply necessary safeguards.

CVE
CVE-2026-68754
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

A repository publisher without delete permission may modify protected package content under specific conditions.