microCLAUDIA version 3.2.0 and earlier contains an improper access-control vulnerability in its API authorization. An authenticated user can submit direct API requests using another organization's identifier to perform actions against that tenant's systems. The flaw breaks tenant isolation and permits cross-organization asset listing and management, agent uninstallation, and deletion of vaccine configurations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository, 'brokeCLAUDIA', provides a Python-based exploit and proof-of-concept tool targeting a broken access control vulnerability in microCLAUDIA (versions 3.2.0 and earlier), a cloud-managed anti-ransomware solution for Windows endpoints. The exploit demonstrates that an authenticated user can access or manipulate data belonging to other organizations by crafting direct API requests with organization identifiers, which may be obtained from browser history or guessed. The repository is well-structured, with core modules for authentication, token handling, endpoint enumeration, and automated/interactive exploitation. It includes a main entry point (main.py) that presents a menu-driven interface for various actions: listing API endpoints, signing in, running PoC exploits (both automated and manual), and extracting organization identifiers from browser history. The endpoints targeted are all under the microCLAUDIA cloud API (microclaudia.ccn-cert.cni.es), and the tool demonstrates both vulnerable and patched scenarios with output samples. The exploit is operational, requiring valid credentials but no elevated privileges, and is not part of a larger exploitation framework. The code is clean, modular, and focused on demonstrating the vulnerability and its impact on cross-tenant data isolation in the microCLAUDIA cloud service.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.