Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deck9
Deck9 deck9 Input |
|
| Vendors & Products |
Deck9
Deck9 deck9 Input |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Access Control Bypass Permitting Webhook Modification in Deck9 Input |
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Access Control Bypass Permitting Webhook Modification in Deck9 Input |
Tue, 16 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Mon, 15 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-06-15T00:00:00.000Z
Updated: 2026-06-16T18:09:13.797Z
Reserved: 2026-06-07T00:00:00.000Z
Link: CVE-2026-50875
Updated: 2026-06-16T18:09:09.507Z
Status : Deferred
Published: 2026-06-15T20:16:30.367
Modified: 2026-06-16T19:16:59.953
Link: CVE-2026-50875
No data.