CVE-2026-82287
CVE-2026-82287 is a high-severity vulnerability with a CVSS 3.x base score of 8.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-942.
Key facts
- Severity: High (CVSS 3.x base score 8.1)
- CVSS v4: 8.6
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-942
- Published:
- Last modified:
Description
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user.
Frequently asked questions
- What is CVE-2026-82287?
- Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user.
- How severe is CVE-2026-82287?
- CVE-2026-82287 has a CVSS 3.x base score of 8.1, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-82287 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-82287?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-82287 published?
- CVE-2026-82287 was published on 2026-08-28 and last updated on 2026-09-23.
References
- https://github.com/rybbit-io/rybbit
- https://github.com/rybbit-io/rybbit/blob/v2.6.0/server/src/index.ts
- https://github.com/rybbit-io/rybbit/commit/6f1039bdd3328a84d6700031bc0ce4714020e2f9
- https://github.com/rybbit-io/rybbit/issues/1038
- https://www.vulncheck.com/advisories/rybbit-reflects-any-origin-in-cors-responses-while-allowing-credentials
Other CWE-942 vulnerabilities
- CVE-2025-61163 — Critical (CVSS 9.8): Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains.…
- CVE-2022-26969 — Critical (CVSS 9.8): In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
- CVE-2022-31736 — Critical (CVSS 9.8): A malicious website could have learned the size of a cross-origin resource that supported Range requests. This…
- CVE-2026-34449 — Critical (CVSS 9.6): SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code…
- CVE-2026-30924 — Critical (CVSS 9.6): qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that…
- CVE-2026-9739 — Critical (CVSS 9.4): Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented…