{"id":"PYSEC-2026-290","summary":"BackendAI Missing Authentication for Critical Function","details":"Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.","aliases":["CVE-2025-49652","GHSA-ww28-4m4v-cq4j"],"modified":"2026-07-02T13:00:06.540771639Z","published":"2026-06-29T11:50:38.333670Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49652"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/37fc8f70f9bad2dd01fe2e288f9006e96f9914ed"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/b6d3ddd9e285a7ce59722a37585b9298681eb82f"},{"type":"WEB","url":"https://github.com/lablup/backend.ai/commit/d7704f506e319acff205d91bfca6e2ca92939983"},{"type":"PACKAGE","url":"https://github.com/lablup/backend.ai"},{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-05-backendai-49653"},{"type":"WEB","url":"https://hiddenlayer.com/sai_security_advisor/2025-06-backendai"},{"type":"PACKAGE","url":"https://pypi.org/project/backend-ai"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-ww28-4m4v-cq4j"}],"affected":[{"package":{"name":"backend-ai","ecosystem":"PyPI","purl":"pkg:pypi/backend-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.15.6"},{"introduced":"25.16.0rc1"},{"fixed":"25.19.0rc1"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.1.0","1.2.0","1.3.0","1.4.0","18.12.0","19.3.0","19.3.0a1","19.9.0","20.3.0","20.3.1","20.9.0","20.9.0a1.dev0","21.3.0","22.3.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/backend-ai/PYSEC-2026-290.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}