CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72741

highCVSS 8.1covered by 1 sourcefirst seen 2026-08-13
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.

⚡ Watch CVE-2026-72741

Get an email if CVE-2026-72741 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-72741

CVE.org record

Embed the live status

CVE-2026-72741 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72741 status](https://www.csirts.com/badge/CVE-2026-72741)](https://www.csirts.com/cve/CVE-2026-72741)