CVE-2026-66006 Details
Description
lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to this endpoint to modify security update preferences, disable security communications, and trigger falsified telemetry events using the legitimate installation ID.
An authentication bypass vulnerability has been identified in lakeFS versions through 1.83.0, within the /setup_comm_prefs endpoint. This vulnerability allows unauthenticated attackers to overwrite operator metadata, including email, name, and company, after the initial setup is complete. Exploitation involves sending a POST request to this endpoint to modify communication preferences, disable security update notifications, and generate false telemetry events using the legitimate installation ID.
Users can update to lakeFS version 1.83.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/treeverse/lakeFS/commit/71a45eeb1639d146d34b8effd7e86d077160ed7c | [email protected] | Patch |
| https://github.com/treeverse/lakeFS/issues/10465 | [email protected] | ExploitIssue Tracking |
| https://github.com/treeverse/lakeFS/pull/10499 | [email protected] | Issue TrackingPatch |
| https://www.vulncheck.com/advisories/lakefs-unauthenticated-operator-metadata-overwrite-via-setup-comm-prefs | [email protected] | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lakefs lakefs | <= 1.83.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |