Description
CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.
Published: 2026-09-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Task Access
Action: Immediate Patch
AI Analysis

Impact

CAPEv2 has a flaw where its REST API does not verify ownership of analysis tasks. As a result, any authenticated user can read or delete tasks created by other users. This flaw permits attackers to enumerate all tasks and remove valuable analysis results, compromising the confidentiality of analytic data and the integrity of the analysis repository.

Affected Systems

CAPEv2 from kevoreilly is affected. All installations that include commit 471ee4b or earlier and have not applied the subsequent fix that enforces ownership checks are vulnerable. No specific release numbers are listed in the data provided.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. Attack requires that the user is authenticated; a legitimate user can simply send requests to the task view and delete endpoints to enumerate and delete tasks. Because the check on ownership is missing, the impact is direct and can be executed without additional privileges.

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CAPEv2 to a commit newer than 471ee4b or apply the official patch provided by the maintainers.
  • If an upgrade is not immediately possible, restrict API access to trusted users or insert an additional access‑control layer that validates task ownership before processing view or delete requests.
  • Continuously monitor API logs for abnormal task enumeration or deletion activity and revoke credentials exhibiting suspicious behavior.

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Kevoreilly
Kevoreilly capev2
Vendors & Products Kevoreilly
Kevoreilly capev2

Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.
Title CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Kevoreilly Capev2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:49.283Z

Reserved: 2026-09-13T10:14:52.108Z

Link: CVE-2026-90768

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:36.731Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:01.113

Modified: 2026-09-23T17:17:47.457

Link: CVE-2026-90768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses