Intel

AIKIDO-2026-10512

github.com/athenz/athenz is vulnerable to Missing Authorization

Missing Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 23, 2026

75

High Risk

This Affects:

GOgithub.com/athenz/athenz
1.0.0 - 1.12.38
Fixed in 1.12.39
Are you affected? Scan for Free

TL;DR

An improper authorization issue in AthenZ ZMS allowed authenticated callers with access to deletion endpoints to remove versioned policy assertions or service public key entries without enforcing configured resource ownership checks, enabling unauthorized cross-owner modification of access-control policies and service identity keys.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/athenz/athenz is vulnerable to Missing Authorization in versions 1.0.0 - 1.12.38.

How to fix this

Upgrade the github.com/athenz/athenz library to the patch version.