A vulnerability was found in Node.js up to 22.22.3/24.16.0/26.3.0 . It has been rated as critical . Affected is the function process.report.writeReport of the component Configuration Handler . The manipulation leads to improper access controls. This vulnerability is traded as CVE-2026-48617 . An attack has to be approached locally. There is no exploit available.