CVE-2026-48089
l3montree-dev devguard
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public assets, any authenticated user — including users from a different organization with no membership or role in the affected org/project — can create, update, reapply, and delete VEX rules on those public assets. The same flaw affects the other vulnerability-triage write endpoints exposed under a public asset, including VEX rule create / update / reapply / delete; dependency-vuln event creation (accept / reject / mitigate decisions), batch event crea...
- CVSS
- 7.1
- EPSS
- 0.36% 29.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.20