Back to database
Soon75High7.5VulnerabilityCVE-2026-107589No patch link observed

CVE-2026-107589 — Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.

Published Oct 8, 2026, 03:17 PM UTCIngested 7h agoSource NVD(cve-db)CVE-2026-107589

Description

Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.

CVSS v3.1 base metrics

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
7.5

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Adjacent Network

Attack Vector

AC

Low

Attack Complexity

PR

Low

Privileges Required

UI

Required

User Interaction

S

Changed

Scope

C

High

Confidentiality

I

Low

Integrity

A

Low

Availability