CVE-2026-71278EPSS p50.1%
CVE-2026-71278CVE-2026-71278
Description
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.66% probability of exploitation · percentile 50.1% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-26 |