A vulnerability was found in nodejs Node.js up to 22.23.1/24.18.0/26.5.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Permission Model. The manipulation results in permission issues.
This vulnerability was named CVE-2026-58039. The attack may be performed from remote. There is no available exploit.