CVE-2026-65926: Private Release Bundle versions may be disclosed under specific configurations
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65926?
The severity of CVE-2026-65926 is low with a score of 3.1.
What components are affected by CVE-2026-65926?
CVE-2026-65926 affects the Private Release Bundle versions when specific configurations allow for anonymous access or low-privilege authenticated users.
Who is impacted by CVE-2026-65926?
Anonymous callers or low-privilege authenticated users may be impacted by CVE-2026-65926, as they can potentially learn private Release Bundle names and versions.
How can I mitigate the risk of CVE-2026-65926?
To mitigate the risk of CVE-2026-65926, ensure that anonymous access is disabled and restrict user privileges appropriately.
What type of exposure does CVE-2026-65926 present?
CVE-2026-65926 presents an exposure of private Release Bundle names and versions when specific access configurations are in place.