THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x287-5c68-36wp (medium) — OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

[GHSA] GHSA-x287-5c68-36wp (medium) — OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

medgithub_advisoriesPublished 2026-08-26

GHSA-x287-5c68-36wp Severity: medium CVE: None

OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

## Summary

OpenWISP IPAM is multi-tenant: every `Subnet` belongs to an `organization`, and API access is scoped to the organizations a user belongs to. The CSV **export** endpoint, `Ex

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-x287-5c68-36wp