HIGH
Wei-Shaw
CVE published 2026-08-11
CVE-2026-73079
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T16:17:39.713Z and has not been modified since then. The Sub2API platform, versions from 0.1.135 to 0.1.168, contains a path traversal vulnerability. Authenticated tenants can relay requests to arbitrary upstream endpoints using pooled account credentials via the `POST /responses/*subpath` wildcar [truncated]