AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72741

HIGH · CVSS 8.1 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Rainbond versions up to 6.9.7 are vulnerable due to a broken access control flaw in the CheckToken function, enabling authenticated attackers to manipulate URL paths and access unauthorized resources belonging to other enterprises. This vulnerability allows attackers to bypass enterprise ID verification using valid API tokens, potentially leading to unauthorized access or modification of critical services and configurations. Organizations using affected versions should prioritize remediation to protect sensitive enterprise data and maintain security integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72741
Severity
HIGH
CVSS
8.1
EPSS
0.19%

Original NVD Description

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.