CVE-2026-42031: Ckan Check Access Bypass Via Whitelistcve-2026-42031-ckan-check-access-bypass-via-whitelist
An authorization check (check_access) is gated behind a "not in <allowlist>" conditional. Resources whose identifier is in the allowlist bypass the authorization check entirely. This pattern was the root cause of CVE-2026-42031 in CKAN's datastore_search, where the WHITELISTED_RESOURCES shortcut allowed enumeration of private resources via _table_metadata an