CVE-2024-6908: Yugabytedb Anywhere

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.

Affected products

Published 2024-07-19. Last modified 2026-06-17.