Description
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
Published: 2026-06-20
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the GNU Savannah Administration Savane application up to version 3.17 arises when untrusted data is used as part of the authorization process. This flaw permits attackers to manipulate the authentication flow, potentially granting unauthorized access to restricted areas or elevating privileges. The weakness corresponds to CWE-696, which describes incorrect validation that impacts security controls.

Affected Systems

All instances of GNU Savannah Savane running version 3.17 or earlier are affected. The free software project management system is distributed by the GNU project and is commonly used in open‑source development environments.

Risk and Exploitability

The CVSS score of 3.7 indicates moderate risk. No EPSS score is available, so the likelihood of active exploitation is uncertain. The vulnerability is not listed in CISA’s KEV catalog. Attackers are likely able to trigger the flaw by submitting crafted data through the web interface, though the exact attack vector is not explicitly described in the advisory, so it is inferred that remote input could be used to exploit the authorization check.

Generated by OpenCVE AI on June 21, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the installed Savannah version and upgrade to the latest release (3.18 or later) to eliminate the flaw.
  • If an upgrade is not immediately possible, review the configuration and disable any features that pass untrusted data to the authorization subsystem.
  • Apply strict input validation and sanitization on any data that influences authentication or authorization logic, and monitor logs for anomalous access attempts.

Generated by OpenCVE AI on June 21, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 21 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Untrusted Data in GNU Savannah Savane

Sun, 21 Jun 2026 07:45:00 +0000

Type Values Removed Values Added
Description GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
First Time appeared Gnu
Gnu savane
Weaknesses CWE-696
CPEs cpe:2.3:a:gnu:savane:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu savane
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-20T20:08:05.163Z

Reserved: 2026-06-20T20:08:04.762Z

Link: CVE-2026-56355

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-21T09:30:09Z

Weaknesses