{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hyperdx--1.10.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hyperdx:hyperdx:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-82279"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HyperDX (\u003c= 1.10.1)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","web-application-security"],"_cs_type":"advisory","_cs_vendors":["HyperDX"],"content_html":"\u003cp\u003eHyperDX versions through 1.10.1 contain a critical authorization flaw within their team management API endpoints. Due to a failure to properly enforce role-based access controls (RBAC), any authenticated team member can bypass existing permission tiers to execute administrative functions. An attacker with standard user access can manipulate team settings, including renaming the team, rotating API keys, and removing other users, including the team owner. This vulnerability presents a significant risk to organizational account security and sensitive data access if administrative tokens are compromised. Defenders should identify HyperDX instances and verify the software version against the patched release.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to modify team configurations and gain administrative control over the platform. This may lead to service disruption, account lockout for authorized administrators, or potential exfiltration of sensitive telemetry data via rotated API keys.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch HyperDX instances by upgrading to the latest version that addresses CVE-2026-82279.\u003c/li\u003e\n\u003cli\u003eAudit logs for suspicious activity involving PATCH or DELETE requests directed at /team/ endpoints, specifically monitoring for non-admin accounts performing team management functions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:38:38Z","date_published":"2026-08-28T21:38:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-hyperdx-auth-bypass/","summary":"HyperDX versions through 1.10.1 contain an improper access control vulnerability allowing authenticated users to perform unauthorized administrative actions via team management API endpoints.","title":"Improper Access Control in HyperDX Team Management","url":"https://feed.craftedsignal.io/briefs/2026-08-hyperdx-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - HyperDX (\u003c= 1.10.1)","version":"https://jsonfeed.org/version/1.1"}