CVE-2026-69119: Taubyte Tau
High severity, CVSS 8.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying ownership or access rights to the target project, enabling attackers with any valid GitHub token to invoke bare KV-store operations such as projects.Fetch and project.Delete against any project ID to achieve cross-tenant project takeover.
Affected products
- Taubyte Tau: up to and including 1.1.10
Published 2026-08-11. Last modified 2026-09-24.