{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/capev2--471ee4b/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:capev2:capev2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-90768"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CAPEv2 (\u003c= 471ee4b)"],"_cs_severities":["high"],"_cs_tags":["webserver","idor","api-security"],"_cs_type":"advisory","_cs_vendors":["CAPEv2"],"content_html":"\u003cp\u003eCAPEv2 up to commit 471ee4b contains an insecure direct object reference (IDOR) vulnerability within its REST API endpoints. The software fails to implement proper ownership validation checks for analysis tasks. Consequently, any authenticated user can bypass access controls to enumerate, read, and delete analysis tasks submitted by other users. This vulnerability is significant in shared sandbox environments where multiple researchers or analysts utilize the same CAPEv2 instance, as it allows for unauthorized data exfiltration or the destruction of historical analysis evidence. Defenders should restrict access to the REST API and monitor for suspicious enumeration patterns or unauthorized deletion requests.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to enumerate all tasks within the system and delete arbitrary analyses. This results in loss of integrity for sandbox reporting and unauthorized access to sensitive malware analysis results.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate CAPEv2 to a commit after 471ee4b to ensure task ownership validation is enforced. Implement strict access control lists on the REST API endpoint and monitor web server access logs for anomalous patterns in URL parameters associated with task IDs.\u003c/p\u003e\n","date_modified":"2026-09-13T11:25:42Z","date_published":"2026-09-13T11:25:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-capev2-idor/","summary":"CAPEv2 versions up to commit 471ee4b contain an IDOR vulnerability allowing authenticated users to access and delete arbitrary analysis tasks.","title":"Insecure Direct Object Reference in CAPEv2 REST API","url":"https://feed.craftedsignal.io/briefs/2026-09-capev2-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - CAPEv2 (\u003c= 471ee4b)","version":"https://jsonfeed.org/version/1.1"}