CVE-2026-36453: High severity Rhymix Rhymix vulnerability
Published Sep 13, 2026
·Updated
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
Affected Software
1 affected component
Rhymix Rhymix<2.1.31
Event History
Sep 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Rhymix versions before 2.1.31 are affected. The issue is an insecure direct object reference involving extra variables.
2
What level of access does an attacker need?
The listed vector requires low privileges and does not require user interaction. Exploitation is network-accessible and may allow access to arbitrary files.
3
What is the potential impact?
The vulnerability has a High severity score of 7.4 and is rated for low confidentiality, integrity, and availability impact. Its scope is changed, indicating the impact may extend beyond the initially vulnerable security authority.