CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-69110 — OpenCode Studio before 2.4.4 contains a missing authentication vulnerability tha...

·Source: NIST NVD

Updated:

Executive Summary

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionall

Analysis

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint. CVSS Score: 9.1. Published: 2026-08-04T16:16:28.483.

Indicators of Compromise (1)

CVE (1)
CVE-2026-69110
Source Attribution

Originally published by NIST NVD on Aug 4, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-69703 — Atlas-Livre contains an improper access control vulnerability in the admin contr...

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because t

CVE-2026-69703
NIST NVD
MEDIUMVulnerability

Iran Cyberattacks Against Minnesota Water Systems

Attribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I

Schneier on Security
MEDIUMVulnerability

Burnham Government Could Signal Tougher UK Cyber and AI Regs

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/burnham-government-could-signal-tougher-uk-cyber-ai-regs-image_small-3-a-32413.jpg" align=right hspace=4><b>Attorney Jonathan Armstrong on Labour's Likely Shift to Sovereignty, Data Security</b><br>Andy Burnham's arrival as U.K. prime minister on July 20 could accelerate Labour's push for tougher AI, cyber and data rules. Attorney

Bank Info Security