CVE-2026-54746: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0
Summary
Hatchet is a platform for managing background tasks and AI workflows. From versions 0.40.0 to 0.91.0, the gRPC service (a communication system for different parts of software) failed to verify that a worker ID (a unique identifier for a processing unit) actually belonged to the tenant (a customer's isolated workspace) making the request, allowing an authenticated attacker to interfere with another tenant's workers by changing their settings or disconnecting them, which could disrupt service or compromise data in shared deployments.
Solution / Mitigation
This issue is fixed in version 0.91.1.
Vulnerability Details
6.4(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
network
low
low
none
August 28, 2026
Classification
Affected Vendors
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54746
First tracked: August 28, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%