← Back to search

CVE-2026-71214

9.8 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows an attacker to bypass authentication by manipulating the session_variables object in the request body, overriding the Authorization header's JWT claims without verification.
Exploitability
Exploitation is relatively easy if an attacker can control the request body, as no origin verification is performed.
Blast radius
If exploited, this could lead to unauthorized access and potential full system compromise, as the attacker would have elevated privileges.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to the endpoint where the session_variables object is used.
auth-bypasswebjwt

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.