SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82287

HIGH · CVSS 8.1 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Rybbit versions prior to 2.7.0 are vulnerable due to a CORS misconfiguration that permits attackers to bypass origin restrictions, allowing them to reflect any request origin in Access-Control-Allow-Origin responses while credentials are enabled. This vulnerability enables unauthorized cross-origin requests, potentially exposing sensitive analytics data and account information, and allowing attackers to perform actions on behalf of the victim user. Organizations using Rybbit should prioritize patching to mitigate the risk of credential theft and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82287
Severity
HIGH
CVSS
8.1
EPSS
0.28%

Original NVD Description

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user.