{"id":"CVE-2026-91774","summary":"Yao through v1.0.0-rc22 Missing Authorization via OpenAPI team endpoint","details":"Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to read full team records. Attackers can supply a known team identifier to retrieve sensitive team data including name, description, owner information, and settings without membership verification.","modified":"2026-09-19T03:31:01.100127969Z","published":"2026-09-15T01:20:35.168Z","database_specific":{"cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91774.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91774.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91774"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/yao-through-1.0.0-rc22-missing-authorization-via-openapi-team-endpoint"},{"type":"REPORT","url":"https://github.com/YaoApp/yao/issues/1553"},{"type":"PACKAGE","url":"https://github.com/YaoApp/yao"},{"type":"ARTICLE","url":"https://github.com/YaoApp/yao/blob/v1.0.0-rc22/openapi/oauth/providers/user/team.go#L37-L55"},{"type":"ARTICLE","url":"https://github.com/YaoApp/yao/blob/v1.0.0-rc22/openapi/user/team.go#L80-L149"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yaoapp/yao","events":[{"introduced":"0"},{"fixed":"5774ce8de5a4d832a1808d942f87c60de86c78e7"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.0-rc22"},{"fixed":"v1.0.0-rc22"}]}}],"versions":["v1.0.0-rc21","v1.0.0-rc20","v1.0.0-rc19","v1.0.0-rc18","v1.0.0-rc17","v1.0.0-rc16","v1.0.0-rc15","v1.0.0-rc14","v1.0.0-rc13","v1.0.0-rc12","v1.0.0-rc11","v1.0.0-rc10","v1.0.0-rc9","v1.0.0-rc8","v1.0.0-rc7","v1.0.0-rc6","v1.0.0-rc5","v1.0.0-rc4","v1.0.0-rc3","v1.0.0-rc2","v1.0.0-rc1","v1.0.0-beta22","v1.0.0-beta21","v1.0.0-beta20","v1.0.0-beta19","v1.0.0-beta18","v1.0.0-beta17","v1.0.0-beta16","v1.0.0-beta15","v1.0.0-beta14","v1.0.0-beta13","v1.0.0-beta12","v1.0.0-beta11","v1.0.0-beta10","v1.0.0-beta9","v1.0.0-beta8","v1.0.0-beta7","v1.0.0-beta6","v1.0.0-beta5","v1.0.0-beta4","v1.0.0-beta3","v1.0.0-beta2","v1.0.0-beta","v1.0.0-alpha18","v1.0.0-alpha17","v1.0.0-alpha16","v1.0.0-alpha15","v1.0.0-alpha14","v1.0.0-alpha13","v1.0.0-alpha12","v1.0.0-alpha11","v1.0.0-alpha10","v1.0.0-alpha9","v1.0.0-alpha8","v1.0.0-alpha7","v1.0.0-alpha6","v1.0.0-alpha5","v1.0.0-alpha4","v1.0.0-alpha3","v1.0.0-alpha2","v1.0.0-alpha","v0-final","v0.10.4-rc.1","v0.10.3","v0.10.3-beta2","v0.10.3-beta","v0.10.3-alpha","v0.10.2","v0.10.2-beta2","v0.10.2-beta","v0.10.1","v0.10.1-beta","v0.10.1-alpha","v0.9.2","v0.9.1","v0.9.1-beta","v0.9.1-alpha3","v0.9.1-alpha2","v0.9.1-alpha","v0.9.0","v0.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91774.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}