CVE-2026-63458
— UNSCOREDpublic exploit availablePublished 2026-09-18 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.
Weaknesses
CWE-639
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71420PoC
- UNSCOREDCVE-2026-100177PoC
- MEDIUMCVE-2026-100531PoC
- LOWCVE-2026-100534PoC
- HIGHCVE-2026-100579PoC
- MEDIUMCVE-2026-100609PoC
- HIGHCVE-2026-100610PoC
- HIGHCVE-2026-100612PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.