Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-81505— Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials

Quick assessment

Affected
frain-dev convoy
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述翻译: Convoy 是一个云原生的 Webhooks 网关。在版本 26.6.8 之前,Convoy 的 端点会对 URL 中的项目(projectID)进行访问授权,但其内部的 函数调用 时,仅根据 获取 Source 对象,而未校验该 Source 所属的项目 ID 是否与已授权的项目一致。 这意味着,经过身份验证的用户或持有项目级 API Key 的调用方,可以替换 URL 中其他租户的 Source 标识符,从而获取该 Source 的完整记录,其中包括未脱敏的 AMQP、Kafka、SQS 或

CVSS 7.1 · High EPSS 0.46% · P38

Affected Version Matrix 1

VendorProduct Version RangeStatus
frain-dev convoy < 26.6.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81505

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
Source: CVE Program / CVE List V5
Vulnerability Description
Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID matches the authorized project. An authenticated user or project-scoped API key holder can substitute another tenant's Source identifier and receive that Source's complete record, including unredacted AMQP, Kafka, SQS, or Google PubSub credentials. The list endpoint remains project-scoped; the single-item Source lookup is affected. This issue is fixed in version 26.6.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
frain-dev convoy < 26.6.8 -

II. Public POCs for CVE-2026-81505

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81505

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-81505 (2)

Other References for CVE-2026-81505 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-81505

No comments yet


Leave a comment