← Back to search

CVE-2026-71262

9.8 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The IoTSharp BlobStorageController.cs lacks proper authorization, allowing unauthenticated attackers to manipulate storage endpoints, leading to potential data breaches and unauthorized access.
Exploitability
Exploitation is relatively straightforward as no authentication is required, and the endpoints are publicly accessible.
Blast radius
If exploited, this could result in significant data loss or corruption, impacting the integrity and confidentiality of the IoTSharp system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Apply the [Authorize] attribute to the BlobStorageController.cs endpoints or configure a global authorization FallbackPolicy in Startup.cs.
auth-bypasswebstorage

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/Download/List/Modify/Delete endpoints reachable by unauthenticated remote attackers.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.