Junglewise Threat Intelligence

CVE-2026-53901: Cerebrate mass-assignment vulnerability in CRUD add path

CVE-2026-53901 · Severity: info · CVSS 8.7 · Published 2026-06-11

Technologies: Cerebrate Project Cerebrate. Vendors: Cerebrate Project.

Executive brief

Cerebrate, an open-source orchestration tool, contains a security flaw in how it handles the creation of new records. An attacker can bypass standard security checks to manually set internal identification numbers for new data entries. This could lead to unauthorized data manipulation, the ability to impersonate legitimate objects, or system errors caused by conflicting record IDs.

Technical details

A mass-assignment vulnerability exists in the generic CRUD 'add' path of Cerebrate. The 'add()' handler attempted to remove an attacker-supplied 'id' from the parameters before the input was normalized via the '__massageInput()' function. Because normalization could re-introduce or retain an 'id' field, an attacker could supply a custom identifier that should be server-controlled. This allows for the creation of objects with arbitrary IDs, leading to potential object spoofing or identifier collisions. The vulnerability was addressed in version 1.37 by ensuring the 'id' is removed from the normalized input immediately before entity patching.

Affected products

  • Cerebrate Project Cerebrate before 1.37

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: advisory: NVD publication date

References

Related threats