CVE-2026-54533: vantage6 node has an Improper Access Control issue
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers that are allowed to run on the node.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vantage6 nodeto a version that resolves this vulnerability.Fixed in 5.0.0 - Configuration
Verify and restrict the algorithm containers that are allowed to run on the node; implement an allowlist of only verified/trusted algorithm containers.
vantage6 node algorithm containers allowed to run on node = restrict to verified/trusted containers
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54533?
The severity of CVE-2026-54533 is classified as medium with a score of 6.9.
How do I fix CVE-2026-54533?
To fix CVE-2026-54533, upgrade to version 5.0.0 or later of the Vantage6 node.
What issue does CVE-2026-54533 address?
CVE-2026-54533 addresses an improper access control issue that allows malicious algorithms to access input and output files of other algorithms.
What is the workaround for CVE-2026-54533 before upgrading?
As a workaround for CVE-2026-54533, verify and restrict the algorithm containers that are allowed to run.
Is CVE-2026-54533 applicable to all Vantage6 versions?
CVE-2026-54533 is applicable to all versions of Vantage6 prior to 5.0.0.