CVE-2026-59100
MEDIUMLobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations
Title source: cnaDescription
LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by supplying arbitrary group identifiers. Attackers can invoke the getGroupAgents, updateAgentInGroup, and removeAgentsFromGroup operations without user-scoped predicates to read agent listings, modify agent roles and ordering, and remove agents from chat groups belonging to other users.
References (4)
Core 4
Core References
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/lobechat-broken-object-level-authorization-via-chat-group-agent-operations
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/lobehub/lobehub/issues/16537
Scores
CVSS v3
5.0
EPSS
0.0018
EPSS Percentile
7.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
lobehub/lobehub
< 2.2.9
Published
Jul 02, 2026
Tracked Since
Jul 03, 2026