CVE-2026-82267: Komodo Resource Identifier Disclosure and Audit Log Pollution Before Permission Check
Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess resource names to obtain internal identifiers and insert fraudulent audit log entries misrepresenting privileged operations.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated Komodo user. They need only low-level privileges and network access; no user interaction is required.
What access or information does an attacker need?
The attacker needs to be able to send requests to the /execute or /execute/{variant} handlers and guess resource names. Successful guesses can reveal internal resource identifiers before permission checks occur.
What is the audit-log impact?
An authenticated attacker can cause fraudulent audit entries that misrepresent privileged operations. This can reduce the reliability of audit records when investigating actions or attributing changes.
Which versions are known to be affected?
Komodo through version 2.3.2 is affected.