CVE-2026-107151Medium· 5.9▾ SunlitMissing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71297Medium· 5.4A flaw was found in the maestro gRPC broker
CVE-2026-71299Medium· 6.5A flaw was found in Maestro
CVE-2026-12423High· 7.5A flaw was found in Foreman
CVE-2026-96577High· 7.1A flaw was found in oc-mirror
CVE-2025-12548Critical· 9.0A flaw was found in Eclipse Che che-machine-exec
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)