What is CVE-2026-75109?
A vulnerability (CVE-2026-75109) exists in Determined where the generic task kill, pause, and unpause API endpoints fail to perform proper authorization checks. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own. Immediate patching is recommended for all users.
Azərbaycanca: Determined platformasında API vasitəsilə task kill, pause və unpause əməliyyatlarında avtorizasiya yoxlanışı zəifliyi (CVE-2026-75109) aşkarlanıb. Autentifikasiya olunmuş hücumçu başqa istifadəçilərin tapşırıqlarını dayandıra, dayandırıb davam etdirə bilər. Bütün istifadəçilərə dərhal rəsmi yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which operations in the Determined platform are affected by CVE-2026-75109?
The CVE-2026-75109 vulnerability affects the task kill, pause, and unpause API operations in the Determined platform due to missing authorization checks.
What can an authenticated attacker do by exploiting CVE-2026-75109?
An authenticated attacker can terminate (kill), pause, or unpause tasks belonging to other users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.