What is CVE-2026-73140?
CVE-2026-73140 is a vulnerability in cti-transmute where comment-level access-control rules are not applied during evaluation report exports via the "build_evaluatio" function. This bypasses the normal visibility, privacy, and permission checks enforced during standard comment retrieval. Affected organizations should immediately apply updates and review their report export processes.
Azərbaycanca: CVE-2026-73140, cti-transmute alətində şərh səviyyəli giriş nəzarəti qaydalarının qiymətləndirmə hesabatlarının ixracı zamanı tətbiq edilməməsi zəifliyidir. Bu, normal şərh sorğulama prosesində mövcud olan görünürlük, məxfilik və icazə yoxlamalarının "build_evaluatio" funksiyası zamanı keçilməsinə səbəb olur. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal yeniləmə tətbiq etməli və hesabat ixracı proseslərini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What access-control checks are bypassed through the CVE-2026-73140 vulnerability?
The CVE-2026-73140 vulnerability bypasses the visibility, privacy, and permission checks that are normally enforced during standard comment retrieval.
What should organizations affected by CVE-2026-73140 do?
Affected organizations should immediately apply updates and review their report export processes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.