Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rybbit-io
Rybbit-io rybbit |
|
| Vendors & Products |
Rybbit-io
Rybbit-io rybbit |
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the victim user. | |
| Title | Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials | |
| Weaknesses | CWE-942 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T18:54:47.480Z
Reserved: 2026-08-28T11:12:53.034Z
Link: CVE-2026-82287
Updated: 2026-08-31T16:34:08.673Z
Status : Received
Published: 2026-08-28T20:20:20.243
Modified: 2026-08-31T19:17:18.143
Link: CVE-2026-82287
No data.
OpenCVE Enrichment
Updated: 2026-08-31T11:20:25Z
