HIGH

CVE-2026-64622

Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox

CVSS v3

7.5

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an operator configures a secret, unauthenticated actors can access sensitive approval request details. The GET /approvals/?status=all, GET /approvals/:id, GET /approvals/stats, and GET /approvals/sse routes disclose full ApprovalEntry content including action/target shell-command strings, file paths, justifications, and

Technical details

CVSS v3 Vector
3.1
Published
7/20/2026
Last Modified
7/20/2026

Frequently asked questions

What is CVE-2026-64622?

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an operator configures a secret, unauthenticated actors can access sensitive approval request details. The GET /approvals/?status=all, GET /approvals/:id, GET /approvals/stats, and GET /approvals/sse routes disclose full ApprovalEntry content including action/target shell-command strings, file paths, justifications, and

Is CVE-2026-64622 actively exploited?

A proof-of-concept exploit exists for CVE-2026-64622, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-64622?

CVE-2026-64622 has a CVSS v3 base score of 7.5 (HIGH severity), with vector string 3.1.

Is CVE-2026-64622 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.