CVE-2026-87109 - Ops Manager Sensitive MFA Enrollment Information Exposure in User Listings
CVE ID :CVE-2026-87109
Published : Oct. 9, 2026, 6:17 a.m. | 1 hour, 29 minutes ago
Description :An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 9, 2026, 6:17 a.m. | 1 hour, 29 minutes ago
Description :An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...