CVE-2026-78154

Source
https://cve.org/CVERecord?id=CVE-2026-78154
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78154.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78154
Published
2026-08-23T23:30:09.983Z
Modified
2026-08-25T04:02:57.085948990Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
the-momentum open-wearables Public Invitation-Code Redemption Endpoint user_invitation_code.py redeem_invitation_code missing authentication
Details

A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeeminvitationcode of the file backend/app/api/routes/v1/userinvitationcode.py of the component Public Invitation-Code Redemption Endpoint. The manipulation of the argument code leads to missing authentication. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78154.json"
}
References

Affected packages

Git / github.com/the-momentum/open-wearables

Affected ranges

Type
GIT
Repo
https://github.com/the-momentum/open-wearables
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.6.0"
        },
        {
            "last_affected": "0.6.0"
        },
        {
            "introduced": "0.6.1"
        },
        {
            "last_affected": "0.6.1"
        },
        {
            "introduced": "0.6.2"
        },
        {
            "last_affected": "0.6.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.6.0
0.6.1
0.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78154.json"