HIGH
TarsCloud
CVE published 2026-08-26
CVE-2026-80348
The TarsWeb application, specifically the PatchController.js module, contains a vulnerability that allows unauthorized package deployment, retrieval, deletion, and default deployment changes across applications. This is due to four methods (uploadAndPublish, downloadPackage, deletePatchPackage, and setPatchPackageDefault) lacking AuthService calls for authorization checks. As a result, any authenticated u [truncated]