Description
deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate on another user's session.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Session Hijack
Action: Immediate Mitigation
AI Analysis

Impact

DeepTutor 1.4.0 contains an authorization bypass that arises when a user-controlled object identifier is passed to TurnRuntimeManager.regenerate_last_turn. By supplying a session_id belonging to another user, an attacker can invoke the regeneration operation on an arbitrary session, effectively taking control of that session. The vulnerability allows the attacker to access, modify, or delete the victim’s data, compromising confidentiality, integrity, and availability of the affected user’s session data.

Affected Systems

The affected product is DeepTutor version 1.4.0. Vendor information is not disclosed in the CVE, so all installations of this version are considered potentially impacted. No other vendor or product details are available.

Risk and Exploitability

The CVSS score is not provided and EPSS is not available, but the fact that a remote caller can trigger an operation on another user’s session indicates a high risk. The vulnerability can be exploited remotely by an attacker who can obtain or guess a valid session_id, which does not require local access or privileged user credentials. The vulnerability is not listed in CISA’s KEV catalog, but its impact and the ease of exploitation suggest it should be treated with priority.

Generated by OpenCVE AI on October 1, 2026 at 22:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or remove remote access to TurnRuntimeManager.regenerate_last_turn or enforce strict server‑side validation that the caller owns the session_id being regenerated.
  • Implement rate limiting, CAPTCHAs, or other abuse‑prevention mechanisms on the endpoint used to enumerate or retrieve session identifiers, to make brute‑force attacks impractical.
  • Audit the codebase to ensure that session identifiers cannot be supplied or modified by user input in any other operation, and review all API endpoints that accept session or user identifiers for similar weaknesses.

Generated by OpenCVE AI on October 1, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in DeepTutor via User‑Controlled Object Identifier
First Time appeared Hkuds
Hkuds deeptutor
Weaknesses CWE-285
CWE-639
Vendors & Products Hkuds
Hkuds deeptutor

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate on another user's session.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-01T21:32:19.477Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:02.520

Modified: 2026-10-01T22:17:02.520

Link: CVE-2026-51878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:30:14Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key