Ghostwire

CVE-2026-6355: A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across...

MEDIUM CVSS 5.5 Exploit Available 1 PoC

Published: April 22, 2026 | Last Modified: April 22, 2026

Description

A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configuration.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (1)

Security Coverage (2 articles)

References