CVE-2026-33890: Ts Admin Auth Gated On Loginrequired Config Flag
Authentication enforcement for an admin or non-public endpoint is gated on a global "loginRequired"/"loginEnabled"-style configuration flag. When the flag is false the 401/403 branch is skipped entirely, allowing unauthenticated access to the sensitive endpoint. Make the admin/non-public auth check unconditional (drop the config-flag conjunction). See CVE-20
greprules fetch cve-2026-33890-ts-admin-auth-gated-on-loginrequired-config-flag --engine opengrepDescription
Authentication enforcement for an admin or non-public endpoint is gated on a global "loginRequired"/"loginEnabled"-style configuration flag. When the flag is false the 401/403 branch is skipped entirely, allowing unauthenticated access to the sensitive endpoint. Make the admin/non-public auth check unconditional (drop the config-flag conjunction). See CVE-20
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.