Impact
The vulnerability arises from a missing check that verifies session ownership in the getFirstMob endpoint of OpenReplay. When a client requests a 15‑second pre‑signed S3 download URL for a session’s DOM replay, only the session path and trusts the caller’s tenant membership. Since validateProjectAccess confirms that the project belongs to the requester’s tenant but does not confirm the session belongs to that project, an authenticated user with low privileges can generate a URL for any session belonging to another tenant. This allows the attacker to download the tenant’s replay, exposing early user interaction data in a confidentiality breach.
Affected Systems
The affected product is the OpenReplay self‑hosted session replay suite. Versions from 1.22.0 through 1.26.x – just prior to 1.27.0 – contain the flaw. A fixed version is available starting with 1.27.0, and all later releases are considered secure.
Risk and Exploitability
With a CVSS score of 7.1, the flaw is classified as high impact, yet its EPSS score is below 1%, indicating a very low probability of exploitation at the time of this report. The vulnerability is not listed in the CISA KEV catalog, and it is inferred that no public exploits have been documented. Attackers need only a low‑privilege authenticated account; no special network conditions or elevated permissions are required. The ability to read another tenant’s early session data can support social engineering or further attacks in multi‑tenant deployments, underscoring the real confidentiality risk presented by this defect.
OpenCVE Enrichment