← Back to search

CVE-2026-77165

6.5 MEDIUM

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
Users could not unlock locks placed by other users, potentially leading to data loss or unavailability.
Exploitability
Exploitation requires specific user permissions and locked files; difficult but feasible under certain conditions.
Blast radius
Impact is limited to the affected files and users, but permanent data loss could occur if not addressed.
Prioritized remediation
Ensure all file owners have proper unlock permissions or implement a recovery mechanism for locked files.
auth-bypassdata-losspermissions

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-284

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.