{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vaultmanager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:helicone:vaultmanager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-85178"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VaultManager"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","credential-access","api-security"],"_cs_type":"advisory","_cs_vendors":["Helicone"],"content_html":"\u003cp\u003eCVE-2026-85178 is an authorization bypass vulnerability affecting the Helicone VaultManager component. The vulnerability resides within the \u003ccode\u003egetDecryptedProviderKeyById()\u003c/code\u003e function, which is exposed via the \u003ccode\u003eGET /v1/vault/key/{providerKeyId}\u003c/code\u003e endpoint. Security researchers have determined that this function fails to validate whether the requester's organization identifier matches the organization identifier associated with the requested vault key.\u003c/p\u003e\n\u003cp\u003eConsequently, any authenticated user possessing admin or owner privileges within any organization using the Helicone platform can bypass intended access controls to retrieve decrypted, plaintext credentials. These credentials include sensitive upstream provider API keys for services such as OpenAI, Anthropic, and Amazon Bedrock. The scope of this issue is significant, as it permits unauthorized cross-tenant credential exfiltration, potentially enabling attackers to consume third-party API quotas or gain unauthorized access to LLM services on behalf of the victim organization. This vulnerability was disclosed on September 3, 2026, and is assigned a CVSS v3.1 base score of 7.7.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized retrieval of plaintext API keys belonging to other tenants. This impact includes the potential for financial loss due to unauthorized API usage, exposure of proprietary LLM configurations, and a complete compromise of the credentials protecting downstream AI infrastructure. All organizations utilizing Helicone's vaulting features for API key management are at risk of cross-tenant credential exfiltration if they maintain multiple organizations on the platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit logs for the \u003ccode\u003eGET /v1/vault/key/\u003c/code\u003e endpoint to identify abnormal patterns of access by user accounts.\u003c/li\u003e\n\u003cli\u003eReview all API keys currently managed within the Helicone Vault for evidence of unauthorized usage or rotation requirements.\u003c/li\u003e\n\u003cli\u003eMonitor Helicone vendor announcements for security patches addressing CVE-2026-85178 and apply them immediately upon availability.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for unusually high volumes of requests to the \u003ccode\u003evault/key\u003c/code\u003e path emanating from authenticated administrative accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T15:21:54Z","date_published":"2026-09-03T15:21:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-helicone-auth-bypass/","summary":"An authorization bypass vulnerability in Helicone's VaultManager allows authenticated users to exfiltrate plaintext provider API keys from other organizations due to missing access control checks.","title":"Authorization Bypass in Helicone VaultManager via Provider Key Retrieval","url":"https://feed.craftedsignal.io/briefs/2026-09-helicone-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - VaultManager","version":"https://jsonfeed.org/version/1.1"}