CVE-2026-84298
3.1 LOWpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows an authenticated tenant worker to intercept another tenant's task callback if they know the task UUID and keep a stream open on the same dispatcher process.
- Exploitability
- Exploitation requires knowledge of the target task UUID and access to the same dispatcher process, making it moderately difficult.
- Blast radius
- If exploited, this could lead to unauthorized access to sensitive task results across different tenants.
- Prioritized remediation
- Update to version 0.95.3 or later to mitigate the vulnerability.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map before tenant ownership is verified, and callback delivery resolves that map by task UUID without tenant identity. An authenticated tenant worker that knows another tenant's durable task UUID and keeps a stream open on the same dispatcher process can receive that task's durable callback result payload. UUIDv4 values are not enumerable, and single-tenant deployments are unaffected in practice. This issue is fixed in version 0.95.3.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-639, CWE-862
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-61748PoC
- MEDIUMCVE-2026-69190PoC
- MEDIUMCVE-2026-77516PoC
- MEDIUMCVE-2026-77517PoC
- MEDIUMCVE-2025-71420PoC
- CRITICALCVE-2026-15958
- HIGHCVE-2026-16561
- HIGHCVE-2026-16605
Related by shared AI tags and CWE weakness class. Browse the full archive.