CVE-2026-48722 | nextflow-io Nextflow up to 25.10.5/26.04.2 Auth Plugin AuthCommandImpl.groovy AuthCommandImpl.writeConfig permission assignment

SecurityVulns

A vulnerability, which was classified as problematic, has been found in nextflow-io Nextflow up to 25.10.5/26.04.2. This impacts the function AuthCommandImpl.writeConfig of the file plugins/nf-tower/src/main/io/seqera/tower/plugin/auth/AuthCommandImpl.groovy of the component Auth Plugin. The manipulation leads to incorrect permission assignment.

This vulnerability is uniquely identified as CVE-2026-48722. Local access is required to approach this attack. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More