No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext authorization headers and third-party API credentials, then use them to directly access upstream APIs. | |
| Title | Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints | |
| First Time appeared |
Onyx
Onyx onyx |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:onyx:onyx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Onyx
Onyx onyx |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:55:15.464Z
Reserved: 2026-09-04T13:51:53.585Z
Link: CVE-2026-85700
Updated: 2026-09-04T14:53:27.543Z
Status : Received
Published: 2026-09-04T15:17:49.110
Modified: 2026-09-04T15:17:49.110
Link: CVE-2026-85700
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:45:04Z