Hatchet Dispatcher gRPC Service Missing Tenant Verification
Hatchet versions 0.40.0 to 0.91.0 lack proper tenant verification in Dispatcher gRPC service, allowing authenticated users to manipulate other tenants' workers and cause denial of service on multi-tenant deployments. The vulnerability was fixed in version 0.91.1.
Disclosed 28 August 2026 · Record updated 13 September 2026
Impact
Cross-tenant integrity impact and denial of service on multi-tenant Hatchet Cloud or shared self-hosted deployments through manipulation of worker labels and disconnection
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54746
