CVE-2026-6355 is a multi-tenant web application vulnerability involving insecure direct object references that enables unauthorized users to access and modify sensitive data across different tenant environments. The flaw affects web applications implementing inadequate access controls on tenant-specific resources. The vulnerability carries a CVSS 3.1 score of 6.5 (Medium severity) with a network-based attack vector requiring no authentication or user interaction, making it relatively straightforward to exploit. The impact includes confidentiality and integrity breaches through unauthorized data access and configuration manipulation, though system availability remains unaffected. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog and remains inactive on public exploit lists. The EPSS score of 0.00032 indicates minimal empirical probability of exploitation, placing this CVE in the lower percentile of threat prevalence. Organizations should prioritize remediation based on exposure to vulnerable web applications rather than imminent exploitation threats.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2025-10-02CPE matchmatch criteria | cpe:2.3:a:augmentt:augmentt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.