The /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:
Fixed in v1.83.0. The endpoint now requires proxy_admin role.
Restrict API key distribution. There is no configuration-level workaround.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T21:59:31Z",
"severity": "HIGH",
"nvd_published_at": null,
"cwe_ids": [
"CWE-863"
]
}