
Cloud Vulnerability DB
A community-led vulnerabilities database
The chat.send path reused command authorization to trigger /reset session rotation even though direct session reset is an admin-only control-plane operation.
A write-scoped gateway caller could rotate a target session, archive the prior transcript state, and force a new session id without admin scope.
src/gateway/server-methods/chat.ts, src/auto-reply/reply/session.ts
<= 2026.3.24>= 2026.3.282026.3.28 contains the fix.Fixed by commit be00fcfccb (Gateway: align chat.send reset scope checks).
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."