PatchSiren

daptin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL daptin CVE published 2026-08-10

CVE-2026-72575

The CVE-2026-72575 record describes an improper authorization vulnerability in daptin through v0.12.34. This vulnerability allows unauthenticated remote attackers to read, create, update, and delete usergroup records due to flawed permission check functions in server/permission/permission.go. The functions (CanRead, CanPeek, CanCreate, CanUpdate, CanDelete, CanRefer) return true whenever p.UserId equals t [truncated]