LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-44426

CVE-2026-44426 - Vulnerability Analysis

MediumCVSS: 6.5

Last Updated: May 14, 2026

ShellHub - Broken Access Control

Published: May 13, 2026Updated: May 14, 2026PoC AvailableRemote Exploitable

Overview

ShellHub < 0.24.2 contains an information disclosure vulnerability caused by improper tenant membership checks in GET /api/namespaces/:tenant, letting API key authenticated attackers access full namespace details of any tenant, exploit requires API key authentication.

Severity & Score

Severity: Medium
CVSS Score: 6.5

Impact

Attackers with any API key can access sensitive tenant information including user IDs, emails, roles, and settings across tenants.

Mitigation

Update to version 0.24.2 or later.

Details

CVE ID
CVE-2026-44426
Severity
Medium
CVSS Score
6.5
Type
broken_access_control
Status
confirmed

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N