What is CVE-2026-73652?
CVE-2026-73652 affects vantage6, an open-source privacy-preserving analysis infrastructure, in versions 5.0.2 and earlier. The vulnerability allows one algorithm developer to modify another developer's algorithm while it is pending or under review due to a missing ownership check in the algorithm-store edit permission. Users are advised to update to the latest version immediately.
Azərbaycanca: CVE-2026-73652, vantage6 açıq mənbəli məxfilik qoruyan analiz altyapısının 5.0.2 və əvvəlki versiyalarında aşkarlanmışdır. Bu zəiflik 'algorithm-store' düzəliş icazəsində sahiblik yoxlamasının olmaması səbəbindən bir alqoritm tərtibatçısının digərinin gözləmədə və ya nəzərdən keçirilmədə olan alqoritmini dəyişdirməsinə imkan verir. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Why does CVE-2026-73652 allow one algorithm developer to modify another's algorithm in vantage6?
Because of a missing ownership check in the algorithm-store edit permission in versions 5.0.2 and earlier.
What should vantage6 users do to protect themselves from this vulnerability?
They should update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.