CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55518

criticalCVSS 9.6covered by 2 sourcesfirst seen 2026-06-17
Summary A critical missing authorization flaw exists in Avo's association attach workflow. The UI and GET /resources/:resource/:id/:related/new path can check attach_<association>?, but the actual write endpoint, POST /resources/:resource/:id/:related, does not run the same authorization check before mutating the association. As a result, an authenticated low-privileged Avo user can bypass hidden/disabled attach controls and directly attach related records to a parent record by sending a crafted POST request. In applications where associations represent teams, tenants, roles, projects, users, memberships, ownership, or other authorization-bearing relationships, this can lead to privilege escalation and cross-tenant data exposure. Details The association attach route writes relationships through Avo::AssociationsController#create: config/routes.rb post "/:resource_name/:id/:related_name", to: "associations#create", as: "associations_create" The controller registers an attach authorization callback only for new, not for create: app/controllers/avo/associations_controller.rb before_action :set_attachment_record, only: [:create, :destroy] before_action :authorize_index_action, only: :index before_action :authorize_attach_action, only: :new before_action :authorize_detach_action, only: :destroy The new action is only the form-rendering step. The actual mutation happens in create: def create if create_association create_success_action else create_fail_action end end create_association then attaches the attacker-supplied related record to the parent: def create_association association_name = BaseResource.valid_association_name(@record, association_from_params) perform_action_and_record_errors do if through_reflection? && additional_params.present? new_join_record.save elsif has_many_reflection? || through_reflection? @record.send(association_name) << @attachment_record else @record.send(:"#{association_name}=", @attachment_record) @record.save! end end end The

⚡ Watch CVE-2026-55518

Get an email if CVE-2026-55518 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-55518

CVE.org record

Embed the live status

CVE-2026-55518 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55518 status](https://www.csirts.com/badge/CVE-2026-55518)](https://www.csirts.com/cve/CVE-2026-55518)