CVE-2026-77170: Medium severity Deck config API vulnerability
Published Sep 18, 2026
·Updated
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.
Affected Software
2 affected components
Deck config API
Deck
Event History
Sep 18, 2026
CVE Published
via MITRE·01:26 AM
Data Sourced
via MITRE·01:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user is required. The user does not need to own or have permission to manage the board whose configuration they target.
2
What access is needed to trigger the issue?
The attacker needs access to the Deck config API and must be able to authenticate. No user interaction is required.
3
What is the likely impact?
The issue permits unauthorized changes to board-scoped configuration keys for arbitrary board IDs. The provided severity data indicates integrity impact only, with no stated confidentiality or availability impact.