Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
*
affected
Description
Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is disabled.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
*
Credits
Esteban Tonglet
References
hiddenlayer.com/sai_security_advisor/2025-06-backendai/