Vendor
critical
advisory
Multi-tenant Isolation Bypass in djust via WebSocket/SSE
6 TTPs 1 CVEA vulnerability in djust caused multi-tenant isolation to fail open on WebSocket and SSE paths, allowing unauthorized cross-tenant data disclosure due to improper tenant context propagation.
djust +1
web-application
mass-assignment
cve-2026-61598
remote-code-execution
information-disclosure
cve-2026-61590
idor
broken-access-control
+5
6t
1c
updated
high
advisory
Authentication Bypass in djust LiveViewConsumer
1 TTP 1 CVEAn authentication bypass vulnerability (CVE-2026-55571) in the djust LiveViewConsumer allows unauthenticated attackers to execute event handlers on gated views by maintaining a WebSocket connection after a redirect.
djust
1t
1c