CVE-2026-82267

Summary

Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess resource names to obtain internal identifiers and insert fraudulent audit log entries misrepresenting privileged operations.

Affected Software

VendorProductVersion RangeStatus
moghtechkomodo0 <= 2.3.2affected

Weaknesses

  • CWE-862: Missing Authorization

References