What is CVE-2026-66006?
lakeFS versions up to 1.83.0 contain an authentication bypass vulnerability in the /setup_comm_prefs endpoint. This allows unauthenticated attackers to overwrite operator metadata (such as email, name, and company) after the initial setup is completed. Users should upgrade to the version containing the fix in commit 71a45ee.
Azərbaycanca: lakeFS-in 1.83.0 və əvvəlki versiyalarında /setup_comm_prefs endpoint-ində autentifikasiyadan yan keçmə (authentication bypass) zəifliyi aşkar edilib. Bu, autentifikasiya olunmamış hücumçulara quraşdırma tamamlandıqdan sonra operator metadata-sını (email, ad, şirkət) manipulyasiya etməyə imkan verir. İstifadəçilərə commit 71a45ee ilə düzəldilmiş versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of lakeFS are affected by CVE-2026-66006?
This vulnerability affects lakeFS versions up to and including 1.83.0.
What does the authentication bypass vulnerability CVE-2026-66006 allow an attacker to do?
This vulnerability allows unauthenticated attackers to overwrite operator metadata (such as email, name, and company) through the /setup_comm_prefs endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.