---
id: CVE-2026-72741
title: >-
  Rainbond through 6.9.7 contains a broken access control vulnerability in the
  CheckToken function that allows authenticated attackers to access unauthorized
  enterprise resources by substituting another enterprise's tenant name in URL
  path…
summary: >-
  Rainbond through 6.9.7 contains a broken access control vulnerability in the
  CheckToken function that allows authenticated attackers to access unauthorized
  enterprise resources by substituting another enterprise's tenant name in URL
  path…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-639
published: '2026-08-13'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:35:08.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72741'
references:
  - url: 'https://github.com/goodrain/rainbond/issues/2665'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/rainbond-region-api-cross-enterprise-idor-via-tenant-access
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00256
epssPercentile: 0.15365
ingestedAt: '2026-09-09T21:22:45.534Z'
---

## Overview

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
