SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-66144

HIGH · CVSS 7.5 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The vulnerability allows for a denial of service attack when large remote policy references are manually retrieved via the API, potentially overwhelming the system. Organizations utilizing affected products should prioritize upgrading to version 3.2.3, which mitigates this risk by enforcing a default maximum size limit on data retrieval from remote policies. This is particularly critical for environments that rely heavily on API interactions for policy management.

CVE
CVE-2026-66144
Severity
HIGH
CVSS
7.5
EPSS
0.48%

Original NVD Description

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge policy is retrieved. Users are recommended to upgrade to version 3.2.3, which fixes this issue by imposing a default maximum size on data read from remote policy references.

Related CVEs

Other vulnerabilities affecting the same vendor(s)