Vendor
high
advisory
Improper Access Control in HyperDX Team Management
1 TTP 1 CVEHyperDX versions through 1.10.1 contain an improper access control vulnerability allowing authenticated users to perform unauthorized administrative actions via team management API endpoints.
HyperDX
privilege-escalation
web-application-security
1t
1c
high
advisory
Server-Side Request Forgery in HyperDX via ClickHouse Proxy Test Endpoint
1 rule 2 TTPs 1 CVEAn authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-63731, in HyperDX before version 2.31.0 by manipulating the `host` parameter of the ClickHouse proxy test endpoint, leading to disclosure of internal service response bodies and potential access to internal APIs, container services, and cloud provider metadata.
HyperDX
ssrf
vulnerability
webserver
1r
2t
1c