CVE-2026-54322 Details
Description
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization role update and delete endpoints authorized the caller as an owner of the organization named in the request path, but resolved and mutated the target role by its identifier alone, without verifying the role belonged to that organization. An authenticated user who owns any organization (organizations are self-service) could therefore modify the permissions of, or delete, a role belonging to a different organization, given that role's identifier. This vulnerability is fixed in 0.185.0.
A cross-organization insecure direct object reference vulnerability has been identified in Daytona versions prior to 0.185.0. This issue arises in the organization role update and delete endpoints, which improperly authorize role modifications by only verifying the role's identifier, without ensuring it belongs to the organization of the requester. As a result, an authenticated user who owns any organization could alter or delete roles in other organizations, using the identifiers of those roles. This vulnerability affects multi-tenant deployments, including the managed Daytona platform.
Users are advised to upgrade to Daytona version 0.185.0 or later. The managed Daytona platform has already been updated to this version. Single-organization self-hosted deployments are not vulnerable, as the issue requires a second organization to exploit.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/daytonaio/daytona/security/advisories/GHSA-qxvm-pcfm-qc39 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Daytonaio Daytona | <= 0.184.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion