Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own. | |
| Title | Determined Missing Authorization Check on Generic Task Endpoints | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T20:36:03.396Z
Reserved: 2026-08-17T17:28:41.677Z
Link: CVE-2026-75109
No data.
Status : Received
Published: 2026-08-17T21:16:49.897
Modified: 2026-08-17T21:16:49.897
Link: CVE-2026-75109
No data.
OpenCVE Enrichment
Updated: 2026-08-17T21:30:03Z
Weaknesses