云虫漏洞库

CVE-2026-18640 - The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption. - 漏洞详情

漏洞编号:CVE-2026-18640

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-18640

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-22

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.

相关链接

相关漏洞

« 返回首页