Junglewise Threat Intelligence

CVE-2026-75517: Novu access control bypass in integration mutations

CVE-2026-75517 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: Novu. Vendors: Novu.

Executive brief

Novu is a notification platform that manages integrations with third-party providers. Before version 3.18.0, users with access to one environment could delete, modify, or reconfigure integrations from other environments within the same organization, potentially compromising notification delivery or exposing provider credentials. The 3.18.0 patch only partially addresses this for API-key authentication while leaving dashboard-session behavior vulnerable.

Technical details

An access control vulnerability in Novu's integration mutation endpoints (remove-integration, update-integration, auto-configure-integration, set-integration-as-primary) fails to consistently enforce environment boundaries when looking up integrations by integrationId and organizationId. Attackers with API key or session access to one environment can target integration identifiers from other environments in the same organization. Version 3.18.0 scopes environment-key API authentication but deliberately retains cross-environment behavior for dashboard sessions, leaving the remediation incomplete.

Affected products

  • Novu Novu before 3.18.0

Timeline

  • 2026-09-22: disclosed
  • 2026-06-09: patched: Version 3.18.0 released with partial fix for API-key authentication only

References

Related threats