CVE Explorer
CVE-2026-42202
nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard> middleware. Any user authenticated on the configured guard could call the endpoint and flip boolean attributes on any Nova resource — including users who do not have access to Nova itself (for example, frontend customers sharing the web guard with the Nova admin area). The endpoint also accepted an
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nova-toggle-5","vendor":"almirhodzic","versions":[{"status":"affected","version":"< 1.3.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6c7809de1c548274371596b855e99029bfec52f7bcf75d6a41b9f02646dbce95 · sha256:00f894cfb24cf9f9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6c7809de1c548274371596b855e99029bfec52f7bcf75d6a41b9f02646dbce95 · sha256:00f894cfb24cf9f9… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6c7809de1c548274371596b855e99029bfec52f7bcf75d6a41b9f02646dbce95 · sha256:00f894cfb24cf9f9… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/almirhodzic/nova-toggle-5/releases/tag/v1.3.0","tags":["x_refsource_MISC"],"url":"https://github.com/almirhodzic/nova-toggle-5/releases/tag/v1.3.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6c7809de1c548274371596b855e99029bfec52f7bcf75d6a41b9f02646dbce95 · sha256:00f894cfb24cf9f9… · /containers/cna/references/1
{"name":"https://github.com/almirhodzic/nova-toggle-5/security/advisories/GHSA-f5c8-m5vw-rmgq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/almirhodzic/nova-toggle-5/security/advisories/GHSA-f5c8-m5vw-rmgq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6c7809de1c548274371596b855e99029bfec52f7bcf75d6a41b9f02646dbce95 · sha256:00f894cfb24cf9f9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.