Junglewise Threat Intelligence

CVE-2026-82267: Komodo authorization bypass in /execute handlers

CVE-2026-82267 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Executive brief

Komodo is a deployment and orchestration tool used to build and run software on multiple servers. The vulnerability allows authenticated users to bypass permission checks and view internal resource identifiers, then inject fake audit log entries to misrepresent privileged operations. This could enable attackers to cover their tracks or gain unauthorized insight into system operations.

Technical details

The /execute and /execute/{variant} API handlers in Komodo through version 2.3.2 disclose internal resource identifiers and write audit entries before enforcing permission checks. Authenticated attackers can enumerate resource names to extract internal identifiers (information disclosure) and insert forged audit log entries falsely documenting privileged operations they did not perform. The vulnerability requires valid authentication but does not require elevated privileges; the root cause is premature exposure of identifiers and logging operations before authorization validation. Patches are expected in versions after 2.3.2.

Affected products

  • moghtech Komodo through 2.3.2

Timeline

  • 2026-08-28: disclosed

References