MEDIUM
vantage6 node has an Improper Access Control issue
Published Jun 17, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.50%
Description
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers that are allowed to run on the node.
Affected products
-
- Version < 5.0.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://docs.vantage6.ai/usage/running-the-node/security x_refsource_MISC
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37825 Advisory
- https://github.com/advisories/GHSA-x9f6-9rvm-mmrg Advisory
- https://github.com/vantage6/vantage6/blob/main/docs/release_notes.rst#500 x_refsource_MISC
- https://github.com/vantage6/vantage6/issues/1932 x_refsource_MISC
- https://github.com/vantage6/vantage6/security/advisories/GHSA-x9f6-9rvm-mmrg x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-54533
| Link | Providers | Tags |
|---|---|---|
| https://docs.vantage6.ai/usage/running-the-node/security | x_refsource_MISC | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-37825 | Advisory | |
| https://github.com/advisories/GHSA-x9f6-9rvm-mmrg | Advisory | |
| https://github.com/vantage6/vantage6/blob/main/docs/release_notes.rst#500 | x_refsource_MISC | |
| https://github.com/vantage6/vantage6/issues/1932 | x_refsource_MISC | |
| https://github.com/vantage6/vantage6/security/advisories/GHSA-x9f6-9rvm-mmrg | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54533 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 17, 2026
Updated Jun 18, 2026
Reserved Jun 15, 2026
Link CVE-2026-54533
CISA Vulnrichment
Updated Jun 18, 2026
ENISA EUVD
EUVD-2026-37825 GHSA-X9F6-9RVM-MMRG Assigner GitHub_M
Published Jun 17, 2026
Updated Jun 18, 2026
Exploited since n/a
Link EUVD-2026-37825