vulnti.work

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) an…

Critical CVSS 9.9
CVECVE-2026-15630
First seen2026-09-22 22:01 UTC
Disclosed2026-07-23 21:17 UTC
Last updated2026-09-22 22:01 UTC
Channel statusauto

Summary

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD