CVE-2026-48026 lakeFS Web UI XSS Vulnerability. lakeFS, an open-source tool for managing object storage as Git-like repositories, has a high-severity vulnerability in its Web UI. This vulnerability, identified as CVE-2026-48026, allows cross-site scripting (XSS) attacks due to improper sanitization of markdown files. An attacker with write access to any repository branch can commit a malicious .md object, [truncated]
The lakeFS installation contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint, allowing unauthenticated attackers to overwrite operator metadata, including email, name, and company, after setup completion. The issue is fixed in commit 71a45ee. This CVE record was published on 2026-07-24T15:19:07.353Z and has not been modified since then. The NVD entry is currently Undergoing An [truncated]