CVE-2026-53769
published 2026-09-04CVE-2026-53769: Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.25%
17.1th percentile
Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avo-hq | avo | — | — |
| go-toolset_rhel8 | golang | — | — |
| openshift-gitops-1 | argocd-rhel8 | — | — |
| openshift-gitops-1 | argocd-rhel9 | — | — |
| rhoso-operators | openstack-operator-bundle | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
avo-hq Avo up to 3.31.x Attachment Upload Endpoint improper authorization
vuldb·2026-09-04·CVSS 6.5
CVE-2026-53769 [MEDIUM] avo-hq Avo up to 3.31.x Attachment Upload Endpoint improper authorization
A vulnerability was found in avo-hq Avo up to 3.31.x and classified as problematic. This issue affects some unknown processing of the component Attachment Upload Endpoint. Executing a manipulation can lead to improper authorization.
This vulnerability is tracked as CVE-2026-53769. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
ghsa·2026-07-09
CVE-2026-53769 [MEDIUM] CWE-862 Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
### Summary
Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as `upload_{FIELD_ID}?`.
An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both `update?` and `upload_?` policies deny the operation.
This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies.
### Details
Avo exposes
Red Hat
avo: Avo: Unauthorized attachment modification via authorization bypass
vendor_redhat·2026-09-04·CVSS 6.5
CVE-2026-53769 [MEDIUM] CWE-639 avo: Avo: Unauthorized attachment modification via authorization bypass
avo: Avo: Unauthorized attachment modification via authorization bypass
A flaw was found in Avo. An authenticated user could bypass server-side upload authorization and field-level upload policies. This allows them to replace or add attachment content, including binary content, filename, and content-type metadata, on a record. This could lead to unauthorized modification of data, particularly in multi-role deployments where specific per-record or per-field operations are expected to be enforced by policies.
Package: golang (Red Hat Enterprise Linux 10) - Fix deferred
Package: go-toolset:rhel8/golang (Red Hat Enterprise Linux 8) - Fix deferred
Package: golang (Red Hat Enterprise Linux 9) - Fix deferred
Package: gcc (Red Hat Hardened Images) - Not affected
Package: gcc13 (Red Hat Harde
No detection rules found.
No public exploits indexed.
https://github.com/avo-hq/avo/commit/de12070dbac0cb6a7e2bea357f9697f99e92554chttps://github.com/avo-hq/avo/pull/4520https://github.com/avo-hq/avo/releases/tag/v3.32.0https://github.com/avo-hq/avo/security/advisories/GHSA-pqpw-cvm4-8mv9https://github.com/avo-hq/avo/security/advisories/GHSA-pqpw-cvm4-8mv9
2026-09-04
Published