216.73.217.22

CVE-2026-8629

· Published 14/05/2026 20:17 · Modified 15/05/2026 14:11

Labels: CVE-2026-8629 2026-05-14CVE-2026-8629CWE-639[email protected]

Essential information

Published
14/05/2026 20:17
Modified
15/05/2026 14:11
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
crabbox / crabbox cpe:2.3:a:crabbox:crabbox:<0.12.0:*:*:*:*:*:*:*

References