AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-70547

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Authenticated users lacking repository read permissions can exploit specific conditions to access sensitive package metadata. This vulnerability could lead to unauthorized information disclosure, potentially compromising the integrity of the repository. Organizations using affected products should prioritize remediation to safeguard sensitive data from unauthorized access.

CVE
CVE-2026-70547
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

An authenticated user without repository read permission may access package metadata under specific conditions.