CVE-2026-80348: Missing Authorization in TarsCloud TarsWeb
Description
CVE-2026-80348 is a high-severity vulnerability in TarsCloud TarsWeb versions up to and including 3.0.16. It involves missing authorization checks in four methods of the PatchController.js, allowing authenticated users with limited roles to perform unauthorized actions across applications. These actions include uploading and deploying packages to any server, downloading or deleting packages from any application, and changing the default deployed package. The vulnerability arises because some methods do not call the AuthService to enforce per-application role restrictions, enabling privilege escalation within the TarsWeb console.
CVSS v4.0
Score 8.7high
Affected software
TarsCloud
TarsWeb
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
TarsWeb enforces per-application roles by calling AuthService in controller methods, but four methods in app/controller/patch/PatchController.js lack these authorization calls. The uploadAndPublish method can upload and deploy packages to any server without verifying developer authorization, only checking if the server is registered. Other methods like downloadPackage, deletePatchPackage, and setPatchPackageDefault operate on packages identified by unscoped primary keys, allowing any authenticated user, regardless of scoped roles, to manipulate packages across all applications managed by the console. This results in unauthorized package deployment, retrieval, deletion, and default package changes across applications.
Potential Impact
Any authenticated user, even with roles scoped to unrelated applications, can push and deploy packages on any server managed by TarsWeb, retrieve or delete packages from any application, and alter which package is deployed by default. This can lead to unauthorized code execution, data manipulation, and potential disruption of application deployments across the environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to TarsWeb to trusted users only and monitor for unusual package deployment activities. Avoid granting broad authenticated access to users without verifying their authorization scope. Follow vendor updates closely for any forthcoming patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-26T09:56:49.946Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8ebe7dacd9273b49ba185c
Added to database: 08/26/2026, 10:22:53 UTC
Last enriched: 09/09/2026, 18:52:22 UTC
Last updated: 10/09/2026, 06:48:19 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.