PatchSiren

treeverse CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM treeverse CVE published 2026-07-24

CVE-2026-66006

The lakeFS installation contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint, allowing unauthenticated attackers to overwrite operator metadata, including email, name, and company, after setup completion. The issue is fixed in commit 71a45ee. This CVE record was published on 2026-07-24T15:19:07.353Z and has not been modified since then. The NVD entry is currently Undergoing An [truncated]