CVE-2026-92765: ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
ArcherySec deployments through version 2.0.6 are affected when multiple organizations use the instance. Any authenticated user who can reach the WebScanVulnList endpoint may be able to access findings belonging to another organization.
What does an attacker need to exploit it?
The attacker needs valid authentication and an arbitrary scan identifier. No user interaction is required, and the attacker can use scan identifiers associated with other tenants.
What information could be disclosed?
The endpoint can expose complete web vulnerability data from other organizations, including finding titles, severities, statuses, and analyst notes.