Description
deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Authorization bypass and file overwrite
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in DeepTutor 1.4.0's TutorBotManager.write_bot_file function, which allows a remote user to supply a user‑controlled object identifier. This leads to an authorization bypass that permits enumeration of bot IDs and overwriting of another bot's whitelisted control files via the HTTP tutorbot file route. As a result, an attacker can modify privileged configuration files that govern bot behavior, potentially enabling execution of arbitrary actions or unauthorized bot commands.

Affected Systems

Affected is DeepTutor version 1.4.0. No additional vendor or product versions are documented in the CVE.

Risk and Exploitability

The flaw can be exploited remotely over HTTP without authentication, enabling malicious enumeration and alteration of protected files. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. A CVSS score has not been published, so the precise severity cannot be quantified from the available data. Nonetheless, the ability to overwrite whitelisted control files represents a significant risk to integrity and operational control of the system.

Generated by OpenCVE AI on October 1, 2026 at 22:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Implement strict authentication and authorization checks on the HTTP tutorbot file route to prevent unauthenticated write access.
  • Validate and sanitize all object identifiers before use in file write operations, ensuring only system‑controlled identifiers are accepted.
  • Apply vendor‑issued updates or patches as soon as they become available to address the authorization bypass flaw.

Generated by OpenCVE AI on October 1, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass and Overwrite of TutorBot Whitelisted Control Files in DeepTutor 1.4.0
First Time appeared Hkuds
Hkuds deeptutor
Weaknesses CWE-284
CWE-285
Vendors & Products Hkuds
Hkuds deeptutor

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-01T21:33:01.362Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:02.650

Modified: 2026-10-01T22:17:02.650

Link: CVE-2026-51879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:30:14Z

Weaknesses