Backportal
patch record · rec_2026-09-07_example_acme · sample
✓ signed
2026-09-07 11:02:45Z
CVE-XXXX-XXXXX on acme: notified, verified, patched and proven in 2 h 00
An authorization flaw in a self-hosted open-source tool. High, CVSS 8.1. Fixed upstream in 1.7.5 and 1.8.1. Upgrading remediates. Source: the upstream maintainers' advisory, GHSA and NVD. The flaw and the fix are theirs; the verdicts, the backport, the hunt and this record are Backportal's.
3
instances declared
2
affected and patched
0
indicators of exploitation
2 h 00
time to patch
Verdict per instance
| Instance | Version | Exposure context | Verdict | Action |
|---|---|---|---|---|
| app-eu-1 | 1.6.9 | internet-facing, feature enabled | affected | patched at 10:40Z |
| app-us-1 | 1.6.9 | internet-facing, feature enabled | affected | patched at 10:40Z |
| app-internal | 1.7.5 | internal, feature disabled | fixed | none |
Timeline
| Time (UTC) | Step | What happened |
|---|---|---|
| 2026-09-07 09:02:11Z | Notify | Advisory CVE-XXXX-XXXXX matched declared stack: example tool on 3 instances. |
| 2026-09-07 09:05:40Z | Assess | 2 instances affected (1.6.9). 1 not affected: 1.7.5 includes the fix, and the vulnerable feature is disabled there. |
| 2026-09-07 09:11:02Z | Verify | Exploitability check confirmed the vulnerable condition reachable on app-eu-1 and app-us-1. No attack performed. |
| 2026-09-07 10:40:27Z | Patch | Upstream fix commits backported onto fork acme/example-tool line 1.6. Build, upstream suite and CVE regression test passed. Merge request !412 merged. |
| 2026-09-07 10:58:13Z | Hunt | Hunt queries run on 30 days of logs and application state on both affected instances. No indicators of exploitation. |
| 2026-09-07 11:02:45Z | Prove | Record signed. OpenVEX statements published for 3 instances. Time to patch: 2 h 00 from advisory match. |