Executive brief
Taubyte Tau is a fullstack development platform that manages projects and repositories. A missing authorization vulnerability allows any authenticated user to read or delete any other tenant's project by specifying an arbitrary project ID, even if they have no ownership or access rights to it. This enables attackers to steal project data, disrupt operations, or take over projects belonging to other organizations.
Technical details
The vulnerability is an authorization bypass in the services/auth HTTP service affecting the GET and DELETE /projects/{id} endpoints in Tau v1.1.10. The GitHubTokenHTTPAuth middleware validates only that a caller presents a valid GitHub OAuth token, without checking whether the caller owns or has write access to the target project. Attackers with any valid GitHub token can invoke KV-store operations (projects.Fetch and projects.Delete) against arbitrary project IDs to achieve cross-tenant project takeover. The attack requires network access to the HTTP service and an authenticated GitHub token, but no special privileges. A patch was released on 2026-08-05 (commit f5c9c9c) that binds project routes to the caller's actual repository access, validating write permissions before allowing operations.
Affected products
- Taubyte Tau v1.1.10
Timeline
- 2026-08-11: disclosed: CVE-2026-69119 published
- 2026-08-05: patched: Fix released in commit f5c9c9c311a1ff156814e0c81f186bfd101ec237