Junglewise Threat Intelligence

CVE-2026-62279: LubeLogger missing authorization in vehicle record duplication

CVE-2026-62279 · Severity: high · CVSS 7.1 · Published 2026-09-18

Executive brief

LubeLogger is a self-hosted web application for tracking vehicle maintenance, fuel costs, and repairs. An authenticated user could exploit a missing authorization check to copy maintenance and service records (including attachments and sensitive paths) from other users' vehicles into their own account, exposing private vehicle history and creating persistent unauthorized copies.

Technical details

The DuplicateRecordsToOtherVehicles endpoint in VehicleController.cs authorizes the destination vehicle but fails to validate that the authenticated user owns the source vehicle before copying records. This insecure direct object reference (IDOR) vulnerability allows an authenticated attacker to enumerate and duplicate service, fuel, tax, supply, note, odometer, reminder, plan, inspection, and equipment records across vehicles without proper access control.

Affected products

  • hargata LubeLogger before 1.6.8

Timeline

  • 2026-06-25: patched: Fix committed to main branch
  • 2026-09-18: disclosed

References

Related threats