GHSA-2g9v-7mr5-fgjg
CRITICALCVE-2026-42300The SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw string value as the authenticated userID when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue requests as that user. Where the target user is an organisation admin or owner, this gives the attacker full control ove
- Affected
- >=0, <1.2.2, < 1.2.2
- Fixed in
- 1.2.2
- Weakness
- CWE-288
- Published
- 2026-05-05
- Source
- osv