Junglewise Threat Intelligence

CVE-2026-11852: Debian Debusine broken access control in artifact relations

CVE-2026-11852 · Severity: info · CVSS 5.3 · Published 2026-06-10

Vendors: Debian.

Executive brief

Debusine is a platform used to build and manage Debian-based software distributions. A security flaw allowed unauthorized users, including anonymous visitors, to modify or delete the links between different software components (artifacts) within the system. This could potentially allow an attacker to disrupt software build workflows or cause tasks to process the wrong files, impacting the integrity of the distribution process.

Technical details

A broken access control vulnerability existed in Debusine's artifact relation management. The endpoints for creating and deleting relationships between artifacts only verified 'can_display' (read-only) permissions. Consequently, any user (including anonymous users) who could view an artifact could also create or delete its relationships to other visible artifacts. This could be exploited to manipulate workflows that rely on artifact relationships to locate files for processing. The issue was addressed by implementing 'can_delete' and 'can_create_artifacts' permission checks, requiring appropriate workspace roles (e.g., OWNER) for these actions.

Affected products

  • Debian Debusine Fixed in commit 98104f46dc546a27a0326d5ef728ac7f426c430a

Timeline

  • 2026-03-11: other: Merge request created to fix the issue
  • 2026-03-12: patched: Fix committed to repository
  • 2026-06-10: disclosed: CVE published

References

Related threats