{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/identrail--1.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:identrail:identrail:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Identrail (\u003c 1.0.2)"],"_cs_severities":["high"],"_cs_tags":["idor","github","cloud","saas"],"_cs_type":"advisory","_cs_vendors":["Identrail"],"content_html":"\u003cp\u003eIdentrail is affected by an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-59185) within its GitHub App connection-completion API. The vulnerability exists because the \u003ccode\u003ePOST /v1/workspaces/:workspace_id/projects/:project_id/github/connect/complete\u003c/code\u003e endpoint accepts a client-supplied \u003ccode\u003einstallation_id\u003c/code\u003e from the JSON body or the \u003ccode\u003eX-GitHub-Installation-ID\u003c/code\u003e header without verifying that the installation belongs to the workspace initiating the flow. While the application correctly binds a state token to the caller's workspace, it fails to perform a similar check on the installation ID. An authenticated attacker can provide a victim's \u003ccode\u003einstallation_id\u003c/code\u003e - which is easily enumerable or discoverable - to link the victim's GitHub organization to the attacker's Identrail workspace. Once linked, the platform mints a GitHub App installation access token using the app's own JWT, granting the attacker unauthorized access to read private repository inventories and potentially perform posture scans on the victim's infrastructure. This affects all versions of Identrail prior to 1.0.2.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Identrail platform as a standard tenant.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a legitimate GitHub connection flow via \u003ccode\u003eStartGitHubConnection\u003c/code\u003e to generate a valid \u003ccode\u003estate\u003c/code\u003e token for their own workspace.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the target organization's GitHub App \u003ccode\u003einstallation_id\u003c/code\u003e (a non-secret integer available in webhooks or public redirect URLs).\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to the completion endpoint (\u003ccode\u003e/github/connect/complete\u003c/code\u003e) using their valid \u003ccode\u003estate\u003c/code\u003e token and the target's \u003ccode\u003einstallation_id\u003c/code\u003e in the request header or body.\u003c/li\u003e\n\u003cli\u003eThe Identrail backend verifies the \u003ccode\u003estate\u003c/code\u003e matches the attacker's workspace, satisfying the security check, but fails to validate the \u003ccode\u003einstallation_id\u003c/code\u003e scope.\u003c/li\u003e\n\u003cli\u003eThe platform persists the victim's \u003ccode\u003einstallation_id\u003c/code\u003e as a connection owned by the attacker's workspace.\u003c/li\u003e\n\u003cli\u003eAttacker uses Identrail's internal repository listing services (\u003ccode\u003eListInstallationRepositories\u003c/code\u003e) which mints an access token for the victim's installation.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves private repository lists and metadata from the victim's GitHub account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized cross-tenant disclosure of sensitive repository metadata and private contents belonging to other customer organizations. This allows attackers to perform reconnaissance on victim organizations' codebase structures, potentially identifying proprietary code or configurations for further targeting.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Identrail platform to version 1.0.2 or later immediately to patch CVE-2026-59185.\u003c/li\u003e\n\u003cli\u003ePerform an audit of existing GitHub App connections to identify any unauthorized or unknown installations linked to your workspaces.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side validation that requires the \u003ccode\u003einstallation_id\u003c/code\u003e to be bound to the tenant's identity during the initial GitHub OAuth handshake.\u003c/li\u003e\n\u003cli\u003eReview access logs for the \u003ccode\u003egithub/connect/complete\u003c/code\u003e endpoint for requests where the \u003ccode\u003eX-GitHub-Installation-ID\u003c/code\u003e or JSON body \u003ccode\u003einstallation_id\u003c/code\u003e differs from those associated with legitimate tenant-authorized installation flows.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-10T00:50:43Z","date_published":"2026-09-10T00:50:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-identrail-idor/","summary":"An improper validation vulnerability in Identrail allows authenticated tenants to perform cross-tenant access to private GitHub repository metadata by supplying an arbitrary installation_id during the connection flow.","title":"Identrail Cross-tenant IDOR via GitHub App Installation ID","url":"https://feed.craftedsignal.io/briefs/2026-09-identrail-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Identrail (\u003c 1.0.2)","version":"https://jsonfeed.org/version/1.1"}