elixir-grpc, Authorization Bypass, CVE-2026-48599 (High) -DC-Aug2026-1882

Listen to this Post

In the HTTP-to-gRPC transcoding layer of the `grpc` Hex package, a critical authorization bypass vulnerability exists due to improper parameter merging precedence. The core issue resides in the `Elixir.GRPC.Server.Transcode.map_request/5` function, located in lib/grpc/server/transcode.ex. All three clauses of this function use `Map.merge/2` with path bindings as the first argument, inadvertently assigning them the lowest merge precedence.
Path bindings are extracted by the router from the matched URL template and are intended to be the authoritative source for resource identifiers. However, due to this low precedence, query-string and request-body parameters can silently overwrite these path-bound fields when the decoded protobuf request struct is built. An authenticated attacker who can reach a transcoded endpoint can substitute any path-bound identifier—such as `user_id` from /users/{user_id}/profile—with an arbitrary value.
For example, a request to `GET /users/me/profile?user_id=victim` results in a decoded struct where `user_id` equals “victim” instead of “me”. Similarly, for a POST with body: "", sending `{“user_id”: “victim”}` in the JSON body achieves the same effect. The handler then receives the attacker’s value and performs authorization, multi-tenancy, or ownership checks based on this attacker-controlled data. Consequently, the attacker can read or modify resources belonging to any other user, effectively bypassing all authorization controls. The vulnerability affects all `grpc` versions from 0.8.0 up to, but not including, 1.0.0.

DailyCVE Form:

Platform: elixir-grpc
Version: 0.8.0 – 0.x.x
Vulnerability: Authorization Bypass
Severity: High (CVSS 7.6)
date: 2026-06-15

Prediction: 2026-06-30

What Undercode Say:

Check grpc version in mix.exs
{:grpc, "~> 0.8.0"}
Verify transcoding is enabled in your endpoint configuration
Look for: GRPC.Server.Transcode
Check for routes with path parameters, e.g.:
GET /users/{user_id}/profile
PUT /organizations/{org_id}/settings

Exploit: (Educational Purposes!)

For a GET endpoint with path binding /users/{user_id}/profile
Attacker substitutes "victim" for "me" via query parameter
curl -X GET "https://target.com/users/me/profile?user_id=victim" \
-H "Authorization: Bearer <attacker_token>"
For a POST endpoint with body: ""
Attacker overrides path-bound org_id with another organization's ID
curl -X POST "https://target.com/orgs/attacker_org/settings" \
-H "Authorization: Bearer <attacker_token>" \
-H "Content-Type: application/json" \
-d '{"org_id": "victim_org", "setting": "malicious_value"}'
To identify vulnerable routes, look for API endpoints with
path parameters that are also accepted in query strings or request bodies

Protection:

  • Upgrade to `grpc` version 1.0.0 or later, where the vulnerability is fixed.
  • Input Validation: Implement explicit validation in your handlers to ensure that path-bound fields in the request struct match the authenticated user’s context.
  • Avoid Overlap: Design APIs to not accept path-bound identifiers in query strings or request bodies.

Impact:

  • Authorization Bypass: An authenticated attacker can access or modify resources belonging to any other user.
  • Data Breach: Sensitive data belonging to other users or tenants can be exposed.
  • Privilege Escalation: Attackers can perform actions on behalf of other users, potentially leading to full account takeover.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top