CVE-2026-54533
Received Received - Intake
Privilege Escalation in vantage6 Prior to 5.0.0

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: GitHub, Inc.

Description
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers that are allowed to run on the node.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-18
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
vantage6 vantage6 5.0.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability in vantage6, an open-source infrastructure for privacy preserving analysis, exists in versions prior to 5.0.0. It allows malicious algorithms to potentially access the input and output files of other algorithms running on the same node.

This means that unauthorized algorithms could read sensitive data processed by other algorithms, compromising data privacy.

Version 5.0.0 of vantage6 fixes this issue. As a workaround before upgrading, it is recommended to verify and restrict which algorithm containers are allowed to run on the node.

Impact Analysis

This vulnerability can lead to unauthorized access to sensitive data processed by algorithms within vantage6.

Malicious algorithms could read input and output files of other algorithms, potentially exposing confidential or private information.

Such data breaches can result in loss of data confidentiality, privacy violations, and could undermine trust in the system.

Mitigation Strategies

To mitigate this vulnerability, you should verify and restrict the algorithm containers that are allowed to run on the node.

Additionally, upgrading vantage6 to version 5.0.0 or later will fix the issue.

Compliance Impact

The vulnerability in vantage6 prior to version 5.0.0 allows malicious algorithms to potentially access other algorithms' input and output files, which could lead to unauthorized data exposure.

Such unauthorized access to data could impact compliance with privacy and data protection regulations like GDPR and HIPAA, which require strict controls on data confidentiality and access.

Version 5.0.0 fixes this issue, and as a workaround, it is recommended to verify and restrict the algorithm containers allowed to run on the node to mitigate risks.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54533. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart