Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92750— Harness through 3.3.0 Missing Access Control via infraproviders endpoint

Quick assessment

Affected
harness harness
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述的中文翻译,力求准确传达技术细节: Harness 3.3.0 及之前版本在基础设施提供方(Infrastructure Provider)的读取接口中缺少访问控制验证,允许已认证用户获取其不属于的空间(Spaces)中的提供方配置。攻击者可以通过在 端点传入任意的空间标识符,从而泄露敏感的提供方元数据,包括 Docker 端点、TLS 证书路径以及云项目标识符。 术语说明(供参考): Infrastructure Provider: 基础设施提供方 Spaces: 工作空间(Harness 中的

CVSS 6.5 · Medium EPSS 0.28% · P18

Affected Version Matrix 1

VendorProduct Version RangeStatus
harness harness ≤ 3.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92750

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Harness through 3.3.0 Missing Access Control via infraproviders endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/infraproviders endpoint with arbitrary space identifiers to expose sensitive provider metadata including Docker endpoints, TLS certificate paths, and cloud project identifiers.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
harness harness 0 ~ 3.3.0 -

II. Public POCs for CVE-2026-92750

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92750

请登录查看更多情报信息。

Other References for CVE-2026-92750 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92750

No comments yet


Leave a comment