CVE-2026-54533Medium▾ Sunlitvantage6 node has an Improper Access Control issue
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
Malicious algorithms can potentially access other algorithms input and output files.
Todo
Verify and restrict the algorithm containers that are allowed to run on your node. See here on how to do this.
https://docs.vantage6.ai/usage/running-the-node/security
If you have any questions or comments about this advisory:
vantage6 < 5.0.0Upgrade to a patched release:
vantage6 5.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-24769LowVantage6: No limit on emails sent for password/MFA reset
CVE-2024-27928MediumVantage6: 2FA can be circumvented with hacked email access
CVE-2026-54445MediumVantage6: Set admin user and password from environment or configuration
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration