CVE-2026-15036

MEDIUM

Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization

Title source: cna
STIX 2.1

Description

A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of the file app/api/controller/gitspace/list_all.go of the component gitspaces Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-376787 | Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
https://vuldb.com/vuln/376787
Signature, Permissions Required signature permissions-required
VDB-376787 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/376787/cti
Third Party Advisory third-party-advisory
CVE-2026-15036 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15036
Third Party Advisory third-party-advisory
Submit #851013 | harness gitness 2.28.2 Authorization Bypass
https://vuldb.com/submit/851013
Exploit exploit issue-tracking
https://github.com/harness/harness/issues/3689

Scores

CVSS v3 4.3
EPSS 0.0024
EPSS Percentile 15.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-639
Status published
Products (3)
None/Harness 2.28.0
None/Harness 2.28.1
None/Harness 2.28.2
Published Jul 08, 2026
Tracked Since Jul 08, 2026