What is CVE-2026-67427?
This vulnerability in Flyto2 Core's engine allows unauthenticated workflow parameters to read host environment variables due to a missing allowlist, bypassing default capability policy. Systems running versions before 2.26.6 are affected, and users should upgrade to the patched version immediately.
Azərbaycanca: Flyto2 Core-un icra mühərrikində aşkar edilmiş bu boşluq, autentifikasiyasız iş axını parametrləri vasitəsilə host mühit dəyişənlərinə icazəsiz giriş imkanı yaradır. Versiya 2.26.6-dan əvvəlki sistemlər təsirlənir, buna görə istifadəçilər dərhal yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Flyto2 Core are affected by CVE-2026-67427?
Systems running Flyto2 Core versions before 2.26.6 are affected by this vulnerability.
How can users protect against CVE-2026-67427?
Users should immediately upgrade Flyto2 Core to version 2.26.6 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.