CVE-2026-66006: lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setupcommprefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
lakeFSto a version that resolves this vulnerability.Fixed in 1.83.0Patch 71a45ee
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66006?
CVE-2026-66006 has a medium severity score of 5.3.
How do I fix CVE-2026-66006?
To fix CVE-2026-66006, upgrade to lakeFS version 1.83.1 or later, which resolves the authentication bypass vulnerability.
What type of vulnerability is CVE-2026-66006?
CVE-2026-66006 is an authentication bypass vulnerability affecting the /setup_comm_prefs endpoint of lakeFS.
What are the potential risks associated with CVE-2026-66006?
The risks include unauthorized overwriting of operator metadata such as email, name, and company information.
Who is affected by CVE-2026-66006?
Users of lakeFS versions up to and including 1.83.0 are affected by CVE-2026-66006.