Description
Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/infraproviders endpoint with arbitrary space identifiers to expose sensitive provider metadata including Docker endpoints, TLS certificate paths, and cloud project identifiers.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Infrastructure Provider Configurations
Action: Patch Now
AI Analysis

Impact

Harness through version 3.3.0 omits access control checks in the infrastructure provider read endpoint. This allows an authenticated user to query the GET /api/v1/infraproviders endpoint with any space identifier and retrieve sensitive provider metadata from spaces the user does not belong to. The exposed data includes Docker endpoints, TLS certificate paths, and cloud project identifiers, which could facilitate further attacks or compromise of infrastructure.

Affected Systems

The affected product is Harness, specifically version 3.3.0. Any deployment of this version is vulnerable if it exposes the infraproviders API to authenticated users without space‑level authorization checks.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact with moderate complexity. The EPSS score is below 1%, suggesting a low but non‑zero probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV, so no known active exploit campaign is reported. Attackers would need valid user credentials but can exploit the flaw within the same application context to exfiltrate sensitive configuration information.

Generated by OpenCVE AI on September 18, 2026 at 06:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Harness to a version that includes the access control fix for the infraproviders endpoint (e.g., the latest release after 3.3.0).
  • Restrict the GET /api/v1/infraproviders endpoint to users who are members of the corresponding space, enforcing role‑based access control.
  • Configure audit logging for all accesses to infraprovider resources and review logs regularly for unauthorized activity.

Generated by OpenCVE AI on September 18, 2026 at 06:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Harness
Harness harness
Vendors & Products Harness
Harness harness

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/infraproviders endpoint with arbitrary space identifiers to expose sensitive provider metadata including Docker endpoints, TLS certificate paths, and cloud project identifiers.
Title Harness through 3.3.0 Missing Access Control via infraproviders endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:25:28.230Z

Reserved: 2026-09-16T18:57:07.770Z

Link: CVE-2026-92750

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:50.295Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:23.720

Modified: 2026-09-24T21:04:40.340

Link: CVE-2026-92750

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:06Z

Weaknesses