Description
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
Published: 2026-09-13
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Arbitrary File Access
Action: Immediate Patch
AI Analysis

Impact

Rhym31 is vulnerable to an insecure direct object reference (IDOR) that allows an attacker to read arbitrary files by supplying additional variables in a request. This flaw can expose sensitive configuration files, user data, or other files stored on the server, leading to a confidentiality breach. The weakness is classified as CWE-425.

Affected Systems

The affected product is Rhymix from the Rhymix organization. Any deployment running Rhymix before version 2.1.31 is vulnerable. The vulnerability is present in all versions older than 2.1.31.

Risk and Exploitability

The CVSS score of 7.4 rates this flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires sending a crafted web request containing extra variables to trigger the IDOR. No authentication or privileged access is mentioned, so the attack may be possible from any external user, implying a wide attack surface.

Generated by OpenCVE AI on September 14, 2026 at 01:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Rhymix to version 2.1.31 or later.
  • If an upgrade is delayed, restrict access to the vulnerable endpoint using IP whitelisting or a web application firewall to block unauthorized requests.
  • Implement strict input validation or sanitization for query parameters to prevent the inclusion of unintended variables.

Generated by OpenCVE AI on September 14, 2026 at 01:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Access via Insecure Direct Object Reference in Rhymix

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
First Time appeared Rhymix
Rhymix rhymix
Weaknesses CWE-425
CPEs cpe:2.3:a:rhymix:rhymix:*:*:*:*:*:*:*:*
Vendors & Products Rhymix
Rhymix rhymix
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-13T20:11:05.324Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36453

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-13T21:16:59.947

Modified: 2026-09-13T21:16:59.947

Link: CVE-2026-36453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T01:45:08Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')