Junglewise Threat Intelligence

CVE-2026-63178: Onyx authorization bypass in user group management

CVE-2026-63178 · Severity: medium · CVSS 6.5 · Published 2026-08-17

Vendors: Onyx.

Executive brief

Onyx is an open-source AI platform that manages user access and document permissions. Prior to version 4.3.0, the Enterprise Edition failed to properly validate permissions when curators modified user groups, allowing a curator to add users to arbitrary groups and gain unauthorized access to documents they should not see. This could result in sensitive data exposure through unauthorized document access.

Technical details

The vulnerability is an authorization bypass in the user group management API endpoints. The PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endpoints in ee/onyx/server/user_group/api.py failed to call the _validate_curator_can_modify_group authorization check when invoking update_user_group and add_users_to_user_group functions in ee/onyx/db/user_group.py. An authenticated curator can exploit this to add arbitrary user accounts to groups they do not manage, then use the get_acl_for_user function and OpenSearch access_control_list filter to access documents assigned to those groups. The vulnerability was fixed in version 4.3.0 by implementing proper authorization validation on curator group modifications.

Affected products

  • Onyx Onyx Enterprise Edition before 4.3.0

Timeline

  • 2026-08-17: disclosed
  • 2026-06-30: patched: Fix released in version 4.3.0

References