What is CVE-2026-15630?
CVE-2026-15630 is a critical multi-tenant boundary bypass vulnerability where a non-global organization admin can delete, create, or modify resources in other tenants by exploiting a mismatch between authorization (based on the `?id=` parameter) and action (based on the request body). Affected systems should immediately patch and review their authorization logic to enforce consistent tenant isolation.
Azərbaycanca: CVE-2026-15630 çox-tenantlı sistemlərdə qeyri-qlobal təşkilat admininin sorğu parametrləri ilə body arasındakı authorization uyğunsuzluğundan istifadə edərək digər tenant-larda resurs yaratmaq, silmək və ya dəyişdirmək imkanı əldə etdiyi kritik sərhəd pozma zəifliyidir. Təsirə məruz qalan çox-tenantlı platformalarda dərhal giriş nəzarəti mexanizmləri nəzərdən keçirilməli və yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What operations can an attacker perform by exploiting CVE-2026-15630?
A non-global organization admin exploiting CVE-2026-15630 can create, delete, or modify resources in other tenants.
What is the root cause of CVE-2026-15630?
The CVE-2026-15630 vulnerability is caused by a mismatch between authorization based on request parameters (e.g., the `?id=` parameter) and the action based on the request body.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.