CVE-2026-92765 Details
Description
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
A vulnerability exists in ArcherySec versions through 2.0.6, where the WebScanVulnList endpoint does not properly validate organization ownership. This flaw allows authenticated users to access vulnerability findings from other organizations. By supplying arbitrary scan identifiers, users can retrieve detailed web vulnerability data, including titles, severities, statuses, and analyst notes, from different tenants.
Users are advised to update to ArcherySec version 2.0.7 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/archerysec/archerysec/issues/676 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/archerysec/archerysec | [email protected] | Source CodeVendor |
| https://github.com/archerysec/archerysec/blob/v2.0.6/webscanners/views.py#L297-L313 | [email protected] | Source CodeVendor |
| https://github.com/archerysec/archerysec/issues/676 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/archerysec-through-2.0.6-information-disclosure-via-webscanvulnlist | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ArcherySec | <= 2.0.6 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion