CVE-2026-33890: Ts Admin Auth Gated On Loginrequired Config Flag

Authentication enforcement for an admin or non-public endpoint is gated on a global "loginRequired"/"loginEnabled"-style configuration flag. When the flag is false the 401/403 branch is skipped entirely, allowing unauthenticated access to the sensitive endpoint. Make the admin/non-public auth check unconditional (drop the config-flag conjunction). See CVE-20

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-33890-ts-admin-auth-gated-on-loginrequired-config-flag --engine opengrep

Description

Authentication enforcement for an admin or non-public endpoint is gated on a global "loginRequired"/"loginEnabled"-style configuration flag. When the flag is false the 401/403 branch is skipped entirely, allowing unauthenticated access to the sensitive endpoint. Make the admin/non-public auth check unconditional (drop the config-flag conjunction). See CVE-20