CVE-2026-81505: Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

Published Sep 18, 2026
·
Updated

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID matches the authorized project. An authenticated user or project-scoped API key holder can substitute another tenant's Source identifier and receive that Source's complete record, including unredacted AMQP, Kafka, SQS, or Google PubSub credentials. The list endpoint remains project-scoped; the single-item Source lookup is affected. This issue is fixed in version 26.6.8.

Affected Software

1 affected component
Convoy<26.6.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Convoy to a version that resolves this vulnerability.

    Fixed in 26.6.8

Event History

Sep 18, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Convoy user or holder of a project-scoped API key can exploit it. They need a source identifier belonging to another tenant and access to the affected single-source endpoint.

2

Which endpoint is affected, and are source listings also exposed?

The affected endpoint is GET /api/v1/projects/{projectID}/sources/{sourceID}. The project-scoped list endpoint is not affected.

3

What information can be disclosed?

A successful cross-tenant lookup returns the complete Source record, including unredacted credentials for AMQP, Kafka, SQS, or Google PubSub.

4

How can I determine whether my deployment is affected?

Convoy versions prior to 26.6.8 are affected. The issue is present when a caller authorized for one project can request a Source ID from another project through the single-item source endpoint and receive its record.

5

What should be done to remediate the issue?

Upgrade Convoy to version 26.6.8, which fixes the authorization check. Until upgraded, restrict access to authenticated users and project-scoped API keys as tightly as possible, since either can invoke the affected endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203