A critical improper authorization flaw tracked as CVE-2026-72575 affects Daptin through v0.12.34, allowing unauthenticated remote attackers to read, create, update, and delete usergroup objects. The bug stems from permission-check logic in Daptin's authorization code that returns true when both the stored owner UserId and the requester's UserId are null, effectively treating guest sessions as authorized owners for records loaded without a user association.
The vulnerable behavior impacts usergroup rows because they are loaded with a null owner and no user_account_id, enabling full CRUD access without credentials. The issue is classified as CWE-284 and carries a CVSS 9.1 score with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. Daptin's repository shows recent work to harden authentication, and defenders are advised to upgrade to a version later than v0.12.34 and enforce authorization checks that reject null or zero-valued user references.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry was published for a critical improper authorization flaw in Daptin through v0.12.34 that lets unauthenticated attackers read, create, update, and delete usergroup records via null owner permission checks in server/permission/permission.go. The entry assigns CVSS 9.1 and recommends updating to a version after v0.12.34 with stricter null-user validation.
The Daptin repository shows the latest commit affecting server/permission/permission.go with the message "harden distributed OTP authentication." This is the only explicitly dated code change referenced in the materials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.