CVE-2026-66006

MEDIUM

lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs

Title source: cna
STIX 2.1

Description

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID.

References (4)

Core 4
Core References
Exploit technical-description exploit issue-tracking
Researcher Disclosure
https://github.com/treeverse/lakeFS/issues/10465
Issue Tracking issue-tracking patch
Pull Request
https://github.com/treeverse/lakeFS/pull/10499

Scores

CVSS v3 5.3
EPSS 0.0031
EPSS Percentile 23.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
lakefs/lakefs < 1.83.0
treeverse/lakeFS < 1.83.0
treeverse/lakeFS 71a45eeb1639d146d34b8effd7e86d077160ed7c
Published Jul 24, 2026
Tracked Since Jul 24, 2026