Description
Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL kind segment to page, icon, or namespace. Attackers who know a private record or module attachment id can request the original or preview route without a token or signature to retrieve files across namespace and record permission boundaries.
Published: 2026-10-11
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Private Attachments
Action: Apply Patch
AI Analysis

Impact

Corteza application versions up to 2024.9.10 allow attackers to download private attachment files without authentication by specifying certain URL kind segments. The vulnerability is an improper authorization flaw (CWE‑863) that permits a lack of permission checks on the compose attachment endpoints. When an attacker knows the identifier of a private record or module attachment, they can request the original or preview route without needing a valid token or signature, thereby exposing files that cross namespace and record permissions.

Affected Systems

The affected product is Corteza, the open‑source business applications platform. Versions released through 2024.9.10 contain the flaw; any installation deploying those versions is susceptible.

Risk and Exploitability

The CVSS score of 8.2 reflects a high severity confidentiality impact, and attackers can exploit the flaw over the public network by sending unauthenticated HTTP requests. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, but the lack of authentication makes the attack likely if the application is exposed. Based on the description, it is inferred that attackers can discover attachment identifiers through enumeration or guessing, which is all that is required to retrieve the files.

Generated by OpenCVE AI on October 11, 2026 at 14:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Corteza to a version newer than 2024.9.10 to apply the vendor‑provided fix.
  • If an immediate upgrade is not possible, restrict access to the compose attachment endpoints so that only authenticated sessions can reach them, e.g., by configuring API gateway rules or firewall restrictions.
  • Verify that the attachment kind parameter is validated against the user's permission set before serving the file, and patch custom code if necessary.

Generated by OpenCVE AI on October 11, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Cortezaproject
Cortezaproject corteza
Vendors & Products Cortezaproject
Cortezaproject corteza

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL kind segment to page, icon, or namespace. Attackers who know a private record or module attachment id can request the original or preview route without a token or signature to retrieve files across namespace and record permission boundaries.
Title Corteza through 2024.9.10 Unauthenticated Attachment Access via Compose Attachment Endpoints
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cortezaproject Corteza
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:37.194Z

Reserved: 2026-10-11T01:52:34.966Z

Link: CVE-2026-108729

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:16.750

Modified: 2026-10-11T13:17:16.750

Link: CVE-2026-108729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses