Impact
A flaw in advisor-backend permits an unauthenticated attacker with network proximity to target the /private/import_content/ endpoint, which lacks authentication and permission validation. This allows the attacker to overwrite the global Advisor rule, resolution, and playbook catalogue. While the catalogue overwrite alone may not directly compromise confidentiality or integrity, it enables an attacker to modify or inject configuration that could lead to arbitrary code execution if combined with additional weaknesses such as unsafe YAML deserialization.
Affected Systems
The vulnerability affects installations of the advisor-backend component. No specific vendor or product sub‑versions are enumerated in the CVE data, so all versions of advisor-backend that expose the /private/import_content/ endpoint without authentication are potentially impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. EPSS data is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The primary attack vector is network adjacent and assumes the attacker can reach the target over the network. The lack of authentication allows any entity with network access to overwrite the global catalogue, potentially leading to malicious configuration changes or, in combination with another flaw, to remote code execution.
OpenCVE Enrichment