Junglewise Threat Intelligence

CVE-2026-82287: Rybbit CORS misconfiguration allowing origin bypass

CVE-2026-82287 · Severity: high · CVSS 8.1 · Published 2026-08-28

Executive brief

Rybbit is an open-source analytics platform designed as a privacy-friendly alternative to Google Analytics. A CORS misconfiguration in versions before 2.7.0 allows attackers to bypass origin restrictions and perform authenticated actions as any victim user, potentially exposing analytics data and enabling unauthorized account modifications through requests originating from malicious websites.

Technical details

The vulnerability is a CORS (Cross-Origin Resource Sharing) misconfiguration where the server reflects the requesting origin directly into the Access-Control-Allow-Origin response header while credentials are enabled. This allows an attacker to craft a malicious website that makes credentialed cross-origin requests to the victim's Rybbit instance. An authenticated user visiting the attacker's site can have their session abused to read sensitive analytics data, access account information, and perform state-changing operations without their knowledge. The vulnerability requires no special privileges; it exploits the browser's same-origin policy bypass via misconfigured CORS. Patching is available in version 2.7.0 and later.

Affected products

  • Rybbit Rybbit before 2.7.0

Timeline

  • 2026-08-28: disclosed

References