CVE-2026-82279

Source
https://cve.org/CVERecord?id=CVE-2026-82279
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82279.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82279
Published
2026-08-28T16:18:59.661Z
Modified
2026-08-30T03:48:23.068467593Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
HyperDX Team Management Operations Missing Role-Based Access Control
Details

HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82279.json",
    "cwe_ids": [
        "CWE-862"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/hyperdxio/hyperdx

Affected ranges

Type
GIT
Repo
https://github.com/hyperdxio/hyperdx
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.10.1"
        },
        {
            "fixed": "1.10.1"
        }
    ]
}

Affected versions

hyperdx@1.*
hyperdx@1.1.0
hyperdx@1.1.1
hyperdx@1.1.2
hyperdx@1.1.3
hyperdx@1.1.4
hyperdx@1.10.0
hyperdx@1.2.0
hyperdx@1.3.0
hyperdx@1.4.0
hyperdx@1.5.0
hyperdx@1.6.0
hyperdx@1.7.0
hyperdx@1.8.0
hyperdx@1.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82279.json"