What is CVE-2026-67426?
CVE-2026-67426 is a critical vulnerability in Flyto2 Core before version 2.26.7. The flyto-verification service exposes an unauthenticated POST /run on port 8344 and uses a client-supplied callback_url to make an outbound request with X-Internal-Key header. This leads to internal key leakage; immediate update to 2.26.7 is recommended.
Azərbaycanca: CVE-2026-67426 Flyto2 Core-un 2.26.7-dən əvvəlki versiyalarında aşkarlanmış kritik boşluqdur. flyto-verification servisi 8344-cü portda autentifikasiyasız `POST /run` sorğusunu qəbul edir və istifadəçidən gələn `callback_url` vasitəsilə daxili açarla sorğu göndərir. Bu, `X-Internal-Key` başlığının sızmasına səbəb olur; dərhal 2.26.7 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Flyto2 Core are affected by CVE-2026-67426?
All versions of Flyto2 Core before 2.26.7 are affected by this vulnerability.
What data can be leaked as a result of CVE-2026-67426?
The vulnerability can lead to the leakage of the X-Internal-Key header, which is an internal authentication key.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.