A vulnerability was found in Node.js up to 22.22.3/24.16.0/26.3.0 . It has been classified as critical . Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2026-48928 . It is possible to initiate the attack remotely. There is no exploit available.