CVE-2026-55881
HIGHOpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint
Title source: cnaDescription
OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProjectAccess checked only that the project belonged to the requester's tenant and did not verify that the session belonged to that project, allowing any authenticated low-privilege user to read another tenant's first 15 seconds of session-replay recording data. This issue is fixed in version 1.27.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/openreplay/openreplay/security/advisories/GHSA-w2x5-m7w5-479h
X_Refsource_Misc x_refsource_misc
https://github.com/openreplay/openreplay/pull/4692
X_Refsource_Misc x_refsource_misc
https://github.com/openreplay/openreplay/commit/ddd09117f644a309c7b040cda0a11ff9433e9e49
X_Refsource_Misc x_refsource_misc
https://github.com/openreplay/openreplay/releases/tag/v1.27.0
Scores
CVSS v4
7.1
EPSS
0.0025
EPSS Percentile
16.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
openreplay/openreplay
>= 1.22.0, < 1.27.0
Published
Jul 10, 2026
Tracked Since
Jul 11, 2026