CVE-2026-18635: Cross Org Impersonation Caller Scope Check

Impersonation permissions are checked against the caller's global scope instead of evaluating access control using the target organization's ACL manager. This can allow cross-tenant authorization bypass and unauthorized privilege escalation across organization boundaries.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-18635-cross-org-impersonation-caller-scope-check --engine opengrep

Description

Impersonation permissions are checked against the caller's global scope instead of evaluating access control using the target organization's ACL manager. This can allow cross-tenant authorization bypass and unauthorized privilege escalation across organization boundaries.