CVE-2026-107151
Awaiting Analysis Awaiting Analysis - Queue

Remote Execution Task Update Authentication Bypass in smart_proxy_dynflow

Vulnerability report for CVE-2026-107151, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
redhat smart_proxy_dynflow *
redhat smart_proxy_dynflow to 1.0.0 (inc)
rubygem smart_proxy_dynflow to 1.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves missing authentication in remote-execution task updates for the smart_proxy_dynflow package. Attackers who know a running job's identifier can send fake job output to mark the job as success or failure without proper authentication. It affects systems using pull or pull-mqtt remote execution modes.

Detection Guidance

Check for unauthorized POST requests to endpoints like /dynflow/tasks/<uuid>/update or /done without valid Authorization headers. Monitor logs for unusual job status updates or manipulated execution plans in pull or pull-mqtt remote execution modes.

Impact Analysis

An attacker could manipulate job results, making a failed job appear successful or vice versa. This could lead to incorrect system records, potential data corruption, or misleading operational status. The impact is limited to job result manipulation and does not allow arbitrary code execution or data theft.

Compliance Impact

This vulnerability could compromise audit trails by falsifying job results, potentially violating compliance requirements for accurate logging and record-keeping. Organizations must ensure job integrity to meet standards like GDPR and HIPAA, which mandate reliable data processing records.

Mitigation Strategies

Apply available security updates for smart_proxy_dynflow. Ensure remote execution is not set to pull or pull-mqtt mode if possible. Restrict network access to the affected endpoints and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107151. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart