{"id":"CVE-2026-71214","published":"2026-08-05T08:16:43.807","lastModified":"2026-08-10T12:17:25.297","description":"The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://github.com/NASA-AMMOS/plandev","tags":[]}],"exploitRefs":[{"url":"https://github.com/NASA-AMMOS/plandev","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to bypass authentication by manipulating the session_variables object in the request body, overriding the Authorization header's JWT claims without verification.","exploitability":"Exploitation is relatively easy if an attacker can control the request body, as no origin verification is performed.","blast_radius":"If exploited, this could lead to unauthorized access and potential full system compromise, as the attacker would have elevated privileges.","remediation":"Disable the affected feature or restrict access to the endpoint where the session_variables object is used.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","jwt"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:00:56.376Z"}}