CVE-2026-92750

Source
https://cve.org/CVERecord?id=CVE-2026-92750
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92750.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92750
Published
2026-09-16T20:32:23Z
Modified
2026-09-19T03:30:27Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Harness through 3.3.0 Missing Access Control via infraproviders endpoint
Details

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/infraproviders endpoint with arbitrary space identifiers to expose sensitive provider metadata including Docker endpoints, TLS certificate paths, and cloud project identifiers.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92750.json"
}
References

Affected packages

Git / github.com/harness/harness

Affected ranges

Type
GIT
Repo
https://github.com/harness/harness
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.3.0"
        },
        {
            "fixed": "3.3.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

Other
unstabledemo
v1.*
v1.0.0-gitspaces-beta
v1.0.1-gitspaces-beta
v1.0.2-gitspaces-beta
v1.0.3-gitspaces-beta
v1.0.4-gitspaces-beta
v3.*
v3.0.0
v3.0.0-beta.1
v3.0.0-beta.10
v3.0.0-beta.2
v3.0.0-beta.3
v3.0.0-beta.4
v3.0.0-beta.5
v3.0.0-beta.6
v3.0.0-beta.7
v3.0.0-beta.8
v3.0.0-beta.9
v3.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92750.json"