CVE-2026-24748 | akuity kargo up to 1.6.2/1.7.6/1.7.x/1.8.6 API Endpoint GetConfig authorization (GHSA-w5wv-wvrp-v5m5)
A vulnerability classified as critical was found in akuity kargo up to 1.6.2/1.7.6/1.7.x/1.8.6. The affected element is the function GetConfig of the component API Endpoint. The manipulation results in incorrect authorization.
This vulnerability is known as CVE-2026-24748. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.