<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>HyperDX (&lt;= 1.10.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/hyperdx--1.10.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 21:38:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/hyperdx--1.10.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Access Control in HyperDX Team Management</title><link>https://feed.craftedsignal.io/briefs/2026-08-hyperdx-auth-bypass/</link><pubDate>Fri, 28 Aug 2026 21:38:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-hyperdx-auth-bypass/</guid><description>HyperDX versions through 1.10.1 contain an improper access control vulnerability allowing authenticated users to perform unauthorized administrative actions via team management API endpoints.</description><content:encoded><![CDATA[<p>HyperDX versions through 1.10.1 contain a critical authorization flaw within their team management API endpoints. Due to a failure to properly enforce role-based access controls (RBAC), any authenticated team member can bypass existing permission tiers to execute administrative functions. An attacker with standard user access can manipulate team settings, including renaming the team, rotating API keys, and removing other users, including the team owner. This vulnerability presents a significant risk to organizational account security and sensitive data access if administrative tokens are compromised. Defenders should identify HyperDX instances and verify the software version against the patched release.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthorized users to modify team configurations and gain administrative control over the platform. This may lead to service disruption, account lockout for authorized administrators, or potential exfiltration of sensitive telemetry data via rotated API keys.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch HyperDX instances by upgrading to the latest version that addresses CVE-2026-82279.</li>
<li>Audit logs for suspicious activity involving PATCH or DELETE requests directed at /team/ endpoints, specifically monitoring for non-admin accounts performing team management functions.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>web-application-security</category></item></channel></rss>