CVE-2026-63116 | deepstreamIO Deepstream up to 10.1.0 Permission Valve rules-map.ts ConfigPermission.canPerformAction permission.type privileges management

SecurityVulns

A vulnerability marked as critical has been reported in deepstreamIO Deepstream up to 10.1.0. This issue affects the function ConfigPermission.canPerformAction of the file src/services/permission/valve/rules-map.ts of the component Permission Valve. This manipulation of the argument permission.type causes improper privilege management.

This vulnerability is handled as CVE-2026-63116. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More