CVE-2026-82452

Source
https://cve.org/CVERecord?id=CVE-2026-82452
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82452.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82452
Published
2026-08-29T13:47:54Z
Modified
2026-10-08T02:52:06Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
rust-iot-platform Authentication Bypass via Missing Request Guards
Details

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without providing valid credentials.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82452.json"
}
References

Affected packages

Git / github.com/iot-ecology/rust-iot-platform

Affected ranges

Type
GIT
Repo
https://github.com/iot-ecology/rust-iot-platform
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82452.json"