Junglewise Threat Intelligence

CVE-2026-6355: Augmentt Web Application IDOR in customerid parameter

CVE-2026-6355 · Severity: medium · CVSS 6.5 · Published 2026-04-22

Technologies: Augmentt Web Application. Vendors: Augmentt.

Executive brief

A security flaw in the Augmentt web application allows unauthorized users to access and modify data belonging to other organizations. By manipulating web requests, an attacker could view sensitive information or change the configuration of different customer accounts. This could lead to data breaches and unauthorized changes to a tenant's environment.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Augmentt web application due to insufficient authorization checks on user-controlled parameters. By intercepting HTTP requests and modifying the 'customerid' parameter, an unauthenticated or low-privileged attacker can access or modify resources belonging to other tenants. This flaw allows for cross-tenant data access, unauthorized resource creation, and potential account creation in other tenants. The vulnerability was reported in versions released before October 2025, and as of the advisory date, no official patch has been confirmed by the vendor.

Affected products

  • Augmentt Augmentt Web Application versions prior to 2025-10-02

Timeline

  • 2025-10-02: other: Initial report sent to vendor
  • 2026-04-16: other: CVE assigned
  • 2026-04-22: disclosed: NVD publication date

References

Related threats