What is CVE-2026-69110?
CVE-2026-69110 is a missing authentication vulnerability in OpenCode Studio versions before 2.4.4. It allows unauthenticated remote attackers to read arbitrary files within the `temp` and `static/music` directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Users should immediately upgrade to version 2.4.4 or later to mitigate the risk.
Azərbaycanca: CVE-2026-69110 OpenCode Studio 2.4.4-dən əvvəlki versiyalarda autentifikasiya çatışmazlığı zəifliyidir. Bu, autentifikasiya olunmamış uzaqdan hücumçulara `/api/tmp/:tmpFile` və `/api/music/:fileName` endpoint-lərinə birbaşa GET sorğuları vasitəsilə `temp` və `static/music` qovluqlarında ixtiyari faylları oxumağa imkan verir. Təsirə məruz qalan sistemlər dərhal 2.4.4 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of OpenCode Studio are affected by CVE-2026-69110?
This missing authentication vulnerability affects OpenCode Studio versions before 2.4.4.
What action can an attacker perform by exploiting CVE-2026-69110?
An unauthenticated remote attacker can read arbitrary files within the `temp` and `static/music` directories by sending GET requests to the `/api/tmp/:tmpFile` and `/api/music/:fileName` endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.