Medium · 5.0 Node.js & npm GHSA-89vx-jh4q-vg3w CVE-2026-63116
deepstream Server 10.1.0: Missing Authorization Check Allows Unauthorized Record Writes (CVE-2026-63116)
A missing authorization rule in deepstream server 10.1.0 allows any authenticated user to bypass write permission checks on PATCH_MULTI record operations when the 'config' permission type is used, enabling unauthorized modification of protected records. Fixed in 10.1.1.
AI summary
A vulnerability has been disclosed in @deepstream/server, a server used by clients and backend services to synchronize data, exchange messages, and perform remote procedure calls at scale. The issue, tracked as CVE-2026-63116, affects version 10.1.0 and involves a gap in the permission system that can let authenticated users bypass write restrictions on certain record operations. The vendor has released version 10.1.1 to address the issue.
What happened
In deepstream server 10.1.0, the file src/services/permission/valve/rules-map.ts omits the PATCH_MULTI record action from the internal RULES_MAP used by the Valve permission system. As a result, when an authenticated client sends a PATCH_MULTI operation while the server is configured with permission.type set to 'config', the function getRulesForMessage returns a null rule specification for that action. The ConfigPermission.canPerformAction logic then treats this missing specification as an unconditional allow, rather than applying the intended RULE_TYPES.WRITE check.
Technical cause
The root cause is a missing authorization entry (CWE-862: Missing Authorization) in the permission rules mapping used to evaluate write access for the PATCH_MULTI record action. Because no rule specification is returned for this action type, the permission check layer silently falls through to an allow decision instead of enforcing the configured write rules.
Why it matters
Any authenticated user can exploit this gap to modify arbitrary protected records that would normally be restricted under the 'config' permission type's write rules. This can lead to corruption of application state or disruption of service availability, since the integrity and consistency of records managed through deepstream can no longer be trusted to follow the server's configured access rules.
Who is affected
Deployments of @deepstream/server running version 10.1.0 with permission.type set to 'config' are affected. Deployments using the default permission type 'none' already allow all operations by design and are not additionally impacted by this specific issue, since they do not rely on the affected write-restriction logic.
Affected versions
@deepstream/server version 10.1.0 is affected. The issue is fixed in version 10.1.1.
Fixes and mitigation
The vendor has released @deepstream/server version 10.1.1, which fixes the missing authorization check by correctly including the PATCH_MULTI action in the permission rules mapping. No alternative mitigation details are provided in the available fact package.
Recommended action
Organizations running @deepstream/server with permission.type set to 'config' should upgrade from version 10.1.0 to version 10.1.1 as soon as possible. Administrators should also review audit logs for any unexpected PATCH_MULTI operations on protected records during the period the vulnerable version was in use.
PatchBriefing score
5.0 / 10 · Medium
Official CVSS: 8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Why this score
This vulnerability has a CVSS base score of 8.8 (High), driven by network attack vector, low attack complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. The PatchBriefing score of 5 reflects that while the technical severity is high, there is no evidence of known exploitation, no public exploit code, and no listing in known-exploited or ransomware-associated catalogs at this time. A fix is available, which further limits the computed score. No EPSS probability data was available at the time of this briefing.
Affected versions
- @deepstream/server = 10.1.0
- vulnerable
- ≥ 10.1.1
- patched
Reported fixes
The vendor has released @deepstream/server version 10.1.1, which fixes the missing authorization check by correctly including the PATCH_MULTI action in the permission rules mapping. No alternative mitigation details are provided in the available fact package.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email