LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-68746

livebook · livebook

Published
CVSS8.8
Severityhigh
WeaknessCWE-636
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected to Livebook Teams caches the identifier of the deployment group it belongs to, and resolves that identifier against a locally cached list of deployment groups on every request in order to decide whether Teams identity enforcement is active. Livebook.Hubs.TeamClient.handle_call/3 in lib/livebook/hubs/team_client.ex does not distinguish a deployment group that could not be resolved from one that was resolved with identity enforcement switched off:

References

← Back to the CVE Tracker

Our coverage of CVE-2026-68746

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-68746.