Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tale
Tale headplane |
|
| Vendors & Products |
Tale
Tale headplane |
Mon, 08 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3. | |
| Title | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user | |
| Weaknesses | CWE-22 CWE-285 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T13:17:53.488Z
Reserved: 2026-05-14T18:06:06.810Z
Link: CVE-2026-46484
Updated: 2026-06-09T13:17:49.723Z
Status : Deferred
Published: 2026-06-08T20:17:01.437
Modified: 2026-06-09T15:25:56.860
Link: CVE-2026-46484
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:56:33Z