CVE-2026-108729
Received Received - Intake

Corteza Improper Authorization Lets Attackers Access Private Attachments

Vulnerability report for CVE-2026-108729, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL kind segment to page, icon, or namespace. Attackers who know a private record or module attachment id can request the original or preview route without a token or signature to retrieve files across namespace and record permission boundaries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cortezaproject corteza 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Corteza through 2024.9.10 has an authorization flaw in compose attachment endpoints. Unauthenticated attackers can exploit this by setting the URL kind segment to page, icon, or namespace to download private attachments. Attackers only need to know a private record or module attachment ID to retrieve files without authentication or proper permissions.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized access attempts to attachment endpoints with URLs containing 'page', 'icon', or 'namespace' without valid authentication tokens. Check server logs for requests to '/compose/attachment/{id}/original' or '/preview' routes with missing or invalid credentials.

Impact Analysis

This vulnerability allows unauthorized access to sensitive files, including private attachments. Attackers could steal confidential data, intellectual property, or personal information stored in attachments across different namespaces and records without detection.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other privacy regulations by enabling unauthorized access to protected data. Organizations may face legal penalties, reputational damage, and loss of customer trust due to data breaches.

Mitigation Strategies

Upgrade Corteza to version 2024.9.10 or later to patch the authorization flaw. If immediate upgrade is not possible, restrict access to attachment endpoints by implementing strict authentication checks and validating URL segments for compose attachments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108729. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart