{"data":{"id":"2caf7b4f-9960-46b0-8d3d-fa6fe161cd97","title":"CVE-2026-54746: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0","summary":"Hatchet is a platform for managing background tasks and AI workflows. From versions 0.40.0 to 0.91.0, the gRPC service (a communication system for different parts of software) failed to verify that a worker ID (a unique identifier for a processing unit) actually belonged to the tenant (a customer's isolated workspace) making the request, allowing an authenticated attacker to interfere with another tenant's workers by changing their settings or disconnecting them, which could disrupt service or compromise data in shared deployments.","solution":"This issue is fixed in version 0.91.1.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54746","publishedAt":"2026-08-28T20:18:17.390Z","cveId":"CVE-2026-54746","cweIds":["CWE-639","CWE-862"],"cvssScore":"6.4","cvssSeverity":"medium","severity":"medium","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Hatchet"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-28T20:18:17.390Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}