What is CVE-2026-69119?
CVE-2026-69119 is a missing authorization vulnerability in Taubyte Tau v1.1.10's services/auth HTTP service. It allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. Immediate application of a security patch is recommended.
Azərbaycanca: CVE-2026-69119, Taubyte Tau v1.1.10-da services/auth HTTP servisində müəyyən edilmiş avtorizasiya çatışmazlığıdır. Bu boşluq autentifikasiya olunmuş istənilən istifadəçiyə, ixtiyari layihə ID-si təqdim etməklə başqa bir təşkilatın layihəsini oxumağa və ya həmişəlik silməyə imkan verir. Təcili olaraq təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What can an attacker do by exploiting CVE-2026-69119?
CVE-2026-69119 is a missing authorization vulnerability that allows any authenticated user to read or permanently delete another tenant's project.
Which version of Taubyte Tau is affected by CVE-2026-69119?
CVE-2026-69119 exists in the services/auth HTTP service of Taubyte Tau v1.1.10.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.