漏洞关键信息 漏洞名称 CMR authorization 漏洞标识 CVE ID: CVE-2026-1237 CVE Advi @ GHSA-j477-6vpg-6c8x 影响版本 Affected versions: 2.9.x, 3.6.x, 4.x 漏洞严重性 Severity: Low (2.1/10) CVSS v4 基础指标 Exploitability Metrics: - Attack Vector: Adjacent - Attack Complexity: High - Attack Requirements: Present - Privileges Required: Low - User interaction: None Vulnerable System Impact Metrics: - Confidentiality: Low - Integrity: Low - Availability: Low Subsequent System Impact Metrics: - Confidentiality: Low - Integrity: Low - Availability: Low 漏洞影响 Impact: Cross-model relation authorization is broken and has a potential security vulnerability. If the controller does not have a root key to verify the macaroon (or if the macaroon has expired), the macaroon cannot be validated and its declared caveats may be used to mint a new macaroon. 临时缓解措施 Workarounds: A proposed PR to address the issue may break model migrations due to the lack of macaroon root keys in model descriptions. 相关漏洞类型 Weaknesses: - CWE-347 - CWE-672 已打补丁版本 Patched versions:** None