CVE-2026-63199
Description
A flaw was found in Perses, an open-source dashboard and visualization project. A low-privilege user with datasource creation rights can exploit a missing authorization check in the datasource proxy. This allows the user to attach a project or global secret they cannot otherwise read and cause Perses to send the decrypted secret in plaintext to a service controlled by the attacker. This bypasses project and global scope separation, leading to the disclosure of sensitive information.
Statement
This Important vulnerability in Perses allows a low-privilege user with datasource creation rights to disclose secrets they are not authorized to read. By attaching a restricted secret to a user-controlled datasource, the Perses proxy can be coerced into sending the decrypted secret in plaintext, bypassing intended access controls. This risk is present in Red Hat products utilizing Perses where users have permissions to create or modify datasources.
Mitigation
No mitigation is currently available for this vulnerability. Red Hat recommends applying the available security update when it becomes available.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.7 | N/A | N/A |
| Attack Vector | Network | N/A | N/A |
| Attack Complexity | Low | N/A | N/A |
| Privileges Required | Low | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Changed | N/A | N/A |
| Confidentiality | High | N/A | N/A |
| Integrity Impact | None | N/A | N/A |
| Availability Impact | None | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability,Access Control
Technical Impact: Modify Memory; Read Memory; Execute Unauthorized Code or Commands; Gain Privileges or Assume Identity; Bypass Protection Mechanism; Other
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.