CVE-2026-66006
MEDIUMlakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs
Title source: cnaDescription
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID.
References (4)
Core 4
Core References
Patch patch
Patch Commit
https://github.com/treeverse/lakeFS/commit/71a45eeb1639d146d34b8effd7e86d077160ed7c
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/treeverse/lakeFS/issues/10465
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/lakefs-unauthenticated-operator-metadata-overwrite-via-setup-comm-prefs
Scores
CVSS v3
5.3
EPSS
0.0031
EPSS Percentile
23.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (3)
lakefs/lakefs
< 1.83.0
treeverse/lakeFS
< 1.83.0
treeverse/lakeFS
71a45eeb1639d146d34b8effd7e86d077160ed7c
Published
Jul 24, 2026
Tracked Since
Jul 24, 2026