CVE-2026-43940: Ai Schema Authtype Missing Profile Constraint
The 'authType' schema field lists 'profiles' as a valid authentication type but omits the constraint that 'authType' must be 'profiles' whenever a profile ID is referenced in the 'profile' field. When this schema object is serialized verbatim into an AI/LLM prompt, the model will generate configurations with an incorrect authType (e.g., 'password'), silently
greprules fetch cve-2026-43940-ai-schema-authtype-missing-profile-constraint --engine opengrepDescription
The 'authType' schema field lists 'profiles' as a valid authentication type but omits the constraint that 'authType' must be 'profiles' whenever a profile ID is referenced in the 'profile' field. When this schema object is serialized verbatim into an AI/LLM prompt, the model will generate configurations with an incorrect authType (e.g., 'password'), silently
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.