An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE)… (CVE-2026-73405)
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed user accounts to subscribe to Server-Sent Events (SSE) streams via the /pubsub/subscribe/<topic> endpoint. This occurred because the SSE interface authenticated requests only by matching the X-API-KEY header without verifying if the account was active and confirmed. As a result, newly created accounts could access SSE streams that should be restricted to active, confirmed users, potentially exposing sensitive streaming data such as unmoderated comments. The issue stems from inconsistent authorization enforcement between the REST API and the SSE streaming interface. A patch has been developed to require accounts to be both active and confirmed before accessing Pub/Sub streams, aligning SSE authorization with the REST API.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-73405) in Vulnerability-Lookup involves an authorization bypass in the Server-Sent Events (SSE) streaming interface. The SSE endpoint /pubsub/subscribe/<topic> uses a token_required decorator that authenticates solely by matching the X-API-KEY header against user API keys but does not check the user's is_active and is_confirmed status. Since API keys are issued during self-registration before account confirmation, attackers can create accounts and immediately use the API key to access SSE streams intended only for active, confirmed users. This exposes potentially sensitive streaming data, including newly submitted or unmoderated content. The root cause is inconsistent authorization checks between the REST API and SSE interface. The patch enforces that accounts must be active and confirmed to access SSE streams, closing the authorization gap.
Potential Impact
The vulnerability allows unauthorized access to SSE streams by inactive or unconfirmed accounts, potentially exposing sensitive or unmoderated data streams that should be restricted. This could lead to information disclosure of data not accessible through the REST API. There is no indication of privilege escalation beyond this data exposure or other impacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The described patch requires accounts to be both active and confirmed before permitting access to Pub/Sub streams, aligning SSE authorization with the REST API. Until a patch is applied, restrict or monitor API key issuance and SSE endpoint access to mitigate unauthorized subscription by inactive or unconfirmed accounts.
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE)… (CVE-2026-73405)
Description
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed user accounts to subscribe to Server-Sent Events (SSE) streams via the /pubsub/subscribe/<topic> endpoint. This occurred because the SSE interface authenticated requests only by matching the X-API-KEY header without verifying if the account was active and confirmed. As a result, newly created accounts could access SSE streams that should be restricted to active, confirmed users, potentially exposing sensitive streaming data such as unmoderated comments. The issue stems from inconsistent authorization enforcement between the REST API and the SSE streaming interface. A patch has been developed to require accounts to be both active and confirmed before accessing Pub/Sub streams, aligning SSE authorization with the REST API.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-73405) in Vulnerability-Lookup involves an authorization bypass in the Server-Sent Events (SSE) streaming interface. The SSE endpoint /pubsub/subscribe/<topic> uses a token_required decorator that authenticates solely by matching the X-API-KEY header against user API keys but does not check the user's is_active and is_confirmed status. Since API keys are issued during self-registration before account confirmation, attackers can create accounts and immediately use the API key to access SSE streams intended only for active, confirmed users. This exposes potentially sensitive streaming data, including newly submitted or unmoderated content. The root cause is inconsistent authorization checks between the REST API and SSE interface. The patch enforces that accounts must be active and confirmed to access SSE streams, closing the authorization gap.
Potential Impact
The vulnerability allows unauthorized access to SSE streams by inactive or unconfirmed accounts, potentially exposing sensitive or unmoderated data streams that should be restricted. This could lead to information disclosure of data not accessible through the REST API. There is no indication of privilege escalation beyond this data exposure or other impacts.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The described patch requires accounts to be both active and confirmed before permitting access to Pub/Sub streams, aligning SSE authorization with the REST API. Until a patch is applied, restrict or monitor API key issuance and SSE endpoint access to mitigate unauthorized subscription by inactive or unconfirmed accounts.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8gv5-4q99-4cxm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-73405"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a7c9b1abf8831d539cda0e4
Added to database: 08/12/2026, 16:11:06 UTC
Last enriched: 08/12/2026, 16:13:39 UTC
Last updated: 08/13/2026, 01:41:07 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.