Description
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of vulnerability data across organizations
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an authenticated user to retrieve vulnerability findings from any organization by supplying arbitrary scan identifiers. The user receives complete web vulnerability data, including titles, severities, statuses, and analyst notes. This exposure violates confidentiality of vulnerability information from other tenants and can lead to strategic or security risks for those organizations. The flaw is an authorization bypass, as the system fails to verify that the requester owns the organization tied to the scan.

Affected Systems

ArcherySec, versions up to and including 2.0.6. The affected component is the WebScanVulnList endpoint of the application.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium to high severity. The EPSS score of less than 1% suggests a low likelihood of the vulnerability being actively exploited at this time. The vulnerability is not listed in the CISA KEV catalog, further indicating it is not a known high‑profile exploit. The attack requires authentication with normal user privileges and can be performed by sending requests to the WebScanVulnList endpoint with crafted scan IDs. Once accessed, an attacker can read data from other tenants without additional privileges.

Generated by OpenCVE AI on September 17, 2026 at 21:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ArcherySec to a release that includes the WebScanVulnList ownership validation fix.
  • Limit endpoint access to users who own the organization owning the scan;
  • Audit role‑based permissions to ensure users cannot request data from organizations they do not own.

Generated by OpenCVE AI on September 17, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
Title ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList
First Time appeared Archerysec
Archerysec archery
Weaknesses CWE-639
CPEs cpe:2.3:a:archerysec:archery:*:*:*:*:*:*:*:*
Vendors & Products Archerysec
Archerysec archery
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Archerysec Archery
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:01:46.321Z

Reserved: 2026-09-16T19:06:21.964Z

Link: CVE-2026-92765

cve-icon Vulnrichment

Updated: 2026-09-17T15:01:43.404Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:25.447

Modified: 2026-09-24T20:48:01.433

Link: CVE-2026-92765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key