Impact
Rainbond through version 6.9.7 has a broken access control flaw in the CheckToken function. An authenticated attacker who possesses a valid API token can substitute another enterprise’s tenant name in the URL path, bypassing the system’s enterprise ID validation. This allows the attacker to see, modify or delete services, plugins, environment variables and certificates that belong to a different enterprise. The vulnerability is an IDOR that compromises the confidentiality and integrity of the affected enterprise’s resources.
Affected Systems
Goodrain’s Rainbond platform versions up to and including 6.9.7 are vulnerable. The issue affects all deployments that expose the Region API and rely on tenant name substitution for enterprise identity checks.
Risk and Exploitability
The CVSS score of 8.6 categorizes the flaw as high severity. The EPSS score is not published and the vulnerability is not listed in the CISA KEV catalog. Attackers need only an authenticated API token, which may be available to compromised or weakly protected users. Once authenticated, they can directly craft requests to the vulnerable endpoint to read or alter resources belonging to other enterprises, making the risk of cross‑enterprise data leakage or sabotage significant.
OpenCVE Enrichment