PatchSiren

TarsCloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH TarsCloud CVE published 2026-08-26

CVE-2026-80348

The TarsWeb application, specifically the PatchController.js module, contains a vulnerability that allows unauthorized package deployment, retrieval, deletion, and default deployment changes across applications. This is due to four methods (uploadAndPublish, downloadPackage, deletePatchPackage, and setPatchPackageDefault) lacking AuthService calls for authorization checks. As a result, any authenticated u [truncated]