A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting… (CVE-2026-15630)
CVE-2026-15630 is a vulnerability where a non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in other tenants. This occurs due to a mismatch between authorization checks based on a query parameter (?id=) and the actual action determined by the request body. No affected versions or patch information are provided, and there are no known exploits in the wild.
AI Analysis
Technical Summary
This vulnerability allows a non-global organization admin within a single tenant environment to circumvent tenant isolation controls. The flaw arises from inconsistent authorization logic: the system authorizes actions based on an identifier passed as a query parameter, but the actual resource modification is determined by the request body, enabling cross-tenant resource manipulation. No CVSS score or detailed severity is available, and no patch or remediation details have been provided.
Potential Impact
An attacker with non-global admin privileges in one tenant can perform unauthorized operations—such as deleting, creating, or modifying resources—in other tenants. This breaks tenant isolation, potentially leading to data integrity issues and unauthorized resource control across tenants.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict non-global admin privileges carefully and monitor for unusual cross-tenant activity if possible.
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting… (CVE-2026-15630)
Description
CVE-2026-15630 is a vulnerability where a non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in other tenants. This occurs due to a mismatch between authorization checks based on a query parameter (?id=) and the actual action determined by the request body. No affected versions or patch information are provided, and there are no known exploits in the wild.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability allows a non-global organization admin within a single tenant environment to circumvent tenant isolation controls. The flaw arises from inconsistent authorization logic: the system authorizes actions based on an identifier passed as a query parameter, but the actual resource modification is determined by the request body, enabling cross-tenant resource manipulation. No CVSS score or detailed severity is available, and no patch or remediation details have been provided.
Potential Impact
An attacker with non-global admin privileges in one tenant can perform unauthorized operations—such as deleting, creating, or modifying resources—in other tenants. This breaks tenant isolation, potentially leading to data integrity issues and unauthorized resource control across tenants.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict non-global admin privileges carefully and monitor for unusual cross-tenant activity if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jhfj-h4g6-q9h9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-15630"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a629b0e9c2644c7f8d86320
Added to database: 07/23/2026, 22:51:58 UTC
Last enriched: 07/23/2026, 22:53:08 UTC
Last updated: 07/24/2026, 03:46:37 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.