CWE-266
AllowedIncorrect Privilege Assignment
Abstraction: Base · Status: Draft
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
2292 vulnerabilities reference this CWE, most recent first.
CVE-2026-101860 (GCVE-0-2026-101860)
Vulnerability from cvelistv5 – Published: 2026-09-29 01:45 – Updated: 2026-09-29 10:44| URL | Tags |
|---|---|
| https://vuldb.com/vuln/411094 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/411094/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101860 | third-party-advisory |
| https://vuldb.com/submit/930259 | third-party-advisory |
| https://gist.github.com/simyat/10422042d6d5225b2b… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| RaspAP | raspap-webgui |
Affected:
3.5.0
Affected: 3.5.1 Affected: 3.5.2 Affected: 3.5.3 Affected: 3.5.4 Affected: 3.5.5 cpe:2.3:a:raspap:raspap-webgui:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101860",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T10:42:39.806516Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T10:44:14.248Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:raspap:raspap-webgui:*:*:*:*:*:*:*:*"
],
"modules": [
"sudo Configuration"
],
"product": "raspap-webgui",
"vendor": "RaspAP",
"versions": [
{
"status": "affected",
"version": "3.5.0"
},
{
"status": "affected",
"version": "3.5.1"
},
{
"status": "affected",
"version": "3.5.2"
},
{
"status": "affected",
"version": "3.5.3"
},
{
"status": "affected",
"version": "3.5.4"
},
{
"status": "affected",
"version": "3.5.5"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "inmoyang (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 9,
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T01:45:15.092Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-411094 | RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/411094"
},
{
"name": "VDB-411094 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/411094/cti"
},
{
"name": "CVE-2026-101860 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101860"
},
{
"name": "Submit #930259 | RaspAP RaspAP WebGUI 3.2.6-3.5.5 Local Privilege Escalation / Insecure Sudo Configuration",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/930259"
},
{
"tags": [
"exploit"
],
"url": "https://gist.github.com/simyat/10422042d6d5225b2beb87754de4b68c"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-28T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-28T17:49:10.000Z",
"value": "VulDB entry last update"
}
],
"title": "RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101860",
"datePublished": "2026-09-29T01:45:15.092Z",
"dateReserved": "2026-09-28T15:43:32.708Z",
"dateUpdated": "2026-09-29T10:44:14.248Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101144 (GCVE-0-2026-101144)
Vulnerability from cvelistv5 – Published: 2026-09-28 20:00 – Updated: 2026-09-29 19:22| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410996 | vdb-entry |
| https://vuldb.com/vuln/410996/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101144 | third-party-advisory |
| https://vuldb.com/submit/894910 | third-party-advisory |
| https://drive.google.com/file/d/16y5IDrRDrARBtGET… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Eleveo | Call Recording Software |
Affected:
9.7.0
cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101144",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T19:22:16.322874Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T19:22:33.219Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*"
],
"modules": [
"Query Builder"
],
"product": "Call Recording Software",
"vendor": "Eleveo",
"versions": [
{
"status": "affected",
"version": "9.7.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "omarelshopky (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:00:07.419Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410996 | Eleveo Call Recording Software Query Builder searchAction.do access control",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/410996"
},
{
"name": "VDB-410996 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410996/cti"
},
{
"name": "CVE-2026-101144 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101144"
},
{
"name": "Submit #894910 | Eleveo Call Recording 9.7.0 Business Logic Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894910"
},
{
"tags": [
"exploit"
],
"url": "https://drive.google.com/file/d/16y5IDrRDrARBtGETXUHhkSgFN38b-c6C/view?usp=sharing"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-28T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-28T10:16:54.000Z",
"value": "VulDB entry last update"
}
],
"title": "Eleveo Call Recording Software Query Builder searchAction.do access control",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101144",
"datePublished": "2026-09-28T20:00:07.419Z",
"dateReserved": "2026-09-28T08:11:27.828Z",
"dateUpdated": "2026-09-29T19:22:33.219Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101054 (GCVE-0-2026-101054)
Vulnerability from cvelistv5 – Published: 2026-09-28 11:45 – Updated: 2026-10-01 14:15| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410916 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410916/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101054 | third-party-advisory |
| https://vuldb.com/submit/928043 | third-party-advisory |
| https://github.com/turretsec/disclosure-thinkware… | exploit |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101054",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:14:55.375807Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:15:07.267Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:thinkware:u3000:*:*:*:*:*:*:*:*"
],
"modules": [
"TCP Service"
],
"product": "U3000",
"vendor": "Thinkware",
"versions": [
{
"status": "affected",
"version": "1.02.04"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "turret (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_supplicant.conf of the component TCP Service. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T11:45:09.155Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410916 | Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410916"
},
{
"name": "VDB-410916 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410916/cti"
},
{
"name": "CVE-2026-101054 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101054"
},
{
"name": "Submit #928043 | Thinkware U3000 up to 1.02.04 Improper Access Controls",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/928043"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/turretsec/disclosure-thinkware-u3000/blob/main/findings/02-arbitrary-file-read.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T18:34:35.000Z",
"value": "VulDB entry last update"
}
],
"title": "Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101054",
"datePublished": "2026-09-28T11:45:09.155Z",
"dateReserved": "2026-09-27T16:26:30.970Z",
"dateUpdated": "2026-10-01T14:15:07.267Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101053 (GCVE-0-2026-101053)
Vulnerability from cvelistv5 – Published: 2026-09-28 11:30 – Updated: 2026-09-28 12:46| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410915 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410915/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101053 | third-party-advisory |
| https://vuldb.com/submit/928042 | third-party-advisory |
| https://github.com/turretsec/disclosure-thinkware… | related |
| https://github.com/tuhttps://github.com/turretsec… | broken-linkexploit |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101053",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T12:46:18.617163Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:46:30.387Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:thinkware:u3000:*:*:*:*:*:*:*:*"
],
"modules": [
"TCP Service"
],
"product": "U3000",
"vendor": "Thinkware",
"versions": [
{
"status": "affected",
"version": "1.02.04"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "turret (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing a manipulation of the argument path can lead to improper access controls. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T11:30:15.930Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410915 | Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410915"
},
{
"name": "VDB-410915 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410915/cti"
},
{
"name": "CVE-2026-101053 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101053"
},
{
"name": "Submit #928042 | Thinkware U3000 up to 1.02.04 Improper Access Controls",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/928042"
},
{
"tags": [
"related"
],
"url": "https://github.com/turretsec/disclosure-thinkware-u3000/blob/main/findings/01-arbitrary-file-write.md"
},
{
"tags": [
"broken-link",
"exploit"
],
"url": "https://github.com/tuhttps://github.com/turretsec/disclosure-thinkware-u3000/blob/main/findings/02-arbitrary-file-read.mdrretsec/disclosure-thinkware-u3000/blob/main/findings/01-arbitrary-file-write.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T18:34:31.000Z",
"value": "VulDB entry last update"
}
],
"title": "Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101053",
"datePublished": "2026-09-28T11:30:15.930Z",
"dateReserved": "2026-09-27T16:26:26.231Z",
"dateUpdated": "2026-09-28T12:46:30.387Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100883 (GCVE-0-2026-100883)
Vulnerability from cvelistv5 – Published: 2026-09-27 22:15 – Updated: 2026-09-28 13:19 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410813 | vdb-entry |
| https://vuldb.com/vuln/410813/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100883 | third-party-advisory |
| https://vuldb.com/submit/916128 | third-party-advisory |
| https://github.com/krayin/laravel-crm/issues/2623 | issue-tracking |
| https://github.com/krayin/laravel-crm/pull/2626 | issue-trackingpatch |
| https://github.com/carlosalbertotuma/advisory/blo… | exploit |
| https://github.com/krayin/laravel-crm/commit/a399… | patch |
| https://github.com/krayin/laravel-crm/releases/ta… | patch |
| https://github.com/krayin/laravel-crm/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| Krayin | laravel-crm |
Affected:
2.2.0
Affected: 2.2.1 Affected: 2.2.2 Affected: 2.2.3 Affected: 2.2.4 Affected: 2.2.5 Unaffected: 2.2.6 cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100883",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:17:44.298727Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:19:18.207Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:*"
],
"product": "laravel-crm",
"vendor": "Krayin",
"versions": [
{
"status": "affected",
"version": "2.2.0"
},
{
"status": "affected",
"version": "2.2.1"
},
{
"status": "affected",
"version": "2.2.2"
},
{
"status": "affected",
"version": "2.2.3"
},
{
"status": "affected",
"version": "2.2.4"
},
{
"status": "affected",
"version": "2.2.5"
},
{
"status": "unaffected",
"version": "2.2.6"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "bl4dsc4n (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fix this issue. This patch is called a399404a388d8ad2700a01349d0d98069c8e85a4. The affected component should be upgraded."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "Improper Access Controls",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T22:15:08.551Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410813 | Krayin laravel-crm acl.php access control",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/410813"
},
{
"name": "VDB-410813 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410813/cti"
},
{
"name": "CVE-2026-100883 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100883"
},
{
"name": "Submit #916128 | Krayin Krayin CRM \u2264 2.2.5 Improper Access Controls",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/916128"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/krayin/laravel-crm/issues/2623"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/krayin/laravel-crm/pull/2626"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/carlosalbertotuma/advisory/blob/main/advisory-05-Missing-Function-Level%20Authorization.md"
},
{
"tags": [
"patch"
],
"url": "https://github.com/krayin/laravel-crm/commit/a399404a388d8ad2700a01349d0d98069c8e85a4"
},
{
"tags": [
"patch"
],
"url": "https://github.com/krayin/laravel-crm/releases/tag/v2.2.6"
},
{
"tags": [
"product"
],
"url": "https://github.com/krayin/laravel-crm/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T06:15:02.000Z",
"value": "VulDB entry last update"
}
],
"title": "Krayin laravel-crm acl.php access control",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100883",
"datePublished": "2026-09-27T22:15:08.551Z",
"dateReserved": "2026-09-27T04:09:48.167Z",
"dateUpdated": "2026-09-28T13:19:18.207Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100619 (GCVE-0-2026-100619)
Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-30 17:20- CWE-266 - Incorrect Privilege Assignment
| URL | Tags |
|---|---|
| https://github.com/Cap-go/capgo.app/security/advi… | vendor-advisory |
| https://www.vulncheck.com/advisories/capgo-ota-ma… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100619",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T17:13:54.114354Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:20:00.856Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/Cap-go/capgo.app/security/advisories/GHSA-443r-w5p8-rhr2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "capgo.app",
"vendor": "Cap-go",
"versions": [
{
"lessThanOrEqual": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Judel777"
}
],
"datePublic": "2026-09-08T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update public.app_versions.manifest on a version whose storage_provider is \u0027r2-direct\u0027, which is not covered by the bundle content-lock check. The on_version_update async worker trusts record.manifest and, using the service-role Supabase client, inserts the attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to the crafted version, the /updates endpoint returns the service-role-created manifest entry as a client-facing download_url, enabling OTA manifest poisoning through a trusted async worker path. All versions are affected; no patch was available at the time of publication."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:20:09.972Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-443r-w5p8-rhr2)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/Cap-go/capgo.app/security/advisories/GHSA-443r-w5p8-rhr2"
},
{
"name": "VulnCheck Advisory: Capgo OTA Manifest Poisoning via app_versions.manifest Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/capgo-ota-manifest-poisoning-via-app-versions-manifest-bypass"
}
],
"title": "Capgo OTA Manifest Poisoning via app_versions.manifest Bypass",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100619",
"datePublished": "2026-09-26T13:22:58.881Z",
"dateReserved": "2026-09-26T02:31:07.602Z",
"dateUpdated": "2026-09-30T17:20:09.972Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97895 (GCVE-0-2026-97895)
Vulnerability from cvelistv5 – Published: 2026-09-25 18:15 – Updated: 2026-09-25 18:40 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/409907 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/409907/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-97895 | third-party-advisory |
| https://vuldb.com/submit/915369 | third-party-advisory |
| https://github.com/krayin/laravel-crm/issues/2616 | issue-tracking |
| https://github.com/krayin/laravel-crm/pull/2621 | issue-trackingpatch |
| https://github.com/carlosalbertotuma/advisory/blo… | exploit |
| https://github.com/krayin/laravel-crm/commit/5469… | patch |
| https://github.com/krayin/laravel-crm/releases/ta… | patch |
| https://github.com/krayin/laravel-crm/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| krayin | laravel-crm |
Affected:
2.2.0
Affected: 2.2.1 Affected: 2.2.2 Affected: 2.2.3 Affected: 2.2.4 Affected: 2.2.5 Unaffected: 2.2.6 cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97895",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T18:40:31.758418Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T18:40:39.301Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:*"
],
"modules": [
"User Management"
],
"product": "laravel-crm",
"vendor": "krayin",
"versions": [
{
"status": "affected",
"version": "2.2.0"
},
{
"status": "affected",
"version": "2.2.1"
},
{
"status": "affected",
"version": "2.2.2"
},
{
"status": "affected",
"version": "2.2.3"
},
{
"status": "affected",
"version": "2.2.4"
},
{
"status": "affected",
"version": "2.2.5"
},
{
"status": "unaffected",
"version": "2.2.6"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "bl4dsc4n (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation of the argument role_id can lead to improper privilege management. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.2.6 is able to mitigate this issue. This patch is called 5469d70336fbb25e8e513683e82b32982ce8aa82. Upgrading the affected component is advised."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T18:15:17.276Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409907 | krayin laravel-crm User Management UserController.php privileges management",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/409907"
},
{
"name": "VDB-409907 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409907/cti"
},
{
"name": "CVE-2026-97895 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-97895"
},
{
"name": "Submit #915369 | Krayin Krayin CRM \u2264 2.2.5 Incorrect Privilege Assignment",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/915369"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/krayin/laravel-crm/issues/2616"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/krayin/laravel-crm/pull/2621"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/carlosalbertotuma/advisory/blob/main/advisory-01-privesc.md"
},
{
"tags": [
"patch"
],
"url": "https://github.com/krayin/laravel-crm/commit/5469d70336fbb25e8e513683e82b32982ce8aa82"
},
{
"tags": [
"patch"
],
"url": "https://github.com/krayin/laravel-crm/releases/tag/v2.2.6"
},
{
"tags": [
"product"
],
"url": "https://github.com/krayin/laravel-crm/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-25T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-25T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-25T12:10:40.000Z",
"value": "VulDB entry last update"
}
],
"title": "krayin laravel-crm User Management UserController.php privileges management",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-97895",
"datePublished": "2026-09-25T18:15:17.276Z",
"dateReserved": "2026-09-25T10:05:20.195Z",
"dateUpdated": "2026-09-25T18:40:39.301Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97324 (GCVE-0-2026-97324)
Vulnerability from cvelistv5 – Published: 2026-09-24 19:15 – Updated: 2026-09-24 19:15| URL | Tags |
|---|---|
| https://vuldb.com/vuln/409332 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/409332/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-97324 | third-party-advisory |
| https://vuldb.com/submit/908275 | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| YunaiV | ruoyi-vue-pro |
Affected:
2026.08
cpe:2.3:a:yunaiv:ruoyi-vue-pro:*:*:*:*:*:*:*:* |
|
| zhijiantianya | ruoyi-vue-pro |
Affected:
2026.08
cpe:2.3:a:zhijiantianya:ruoyi-vue-pro:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:yunaiv:ruoyi-vue-pro:*:*:*:*:*:*:*:*"
],
"modules": [
"Demo-order Payment Callback Handler"
],
"product": "ruoyi-vue-pro",
"vendor": "YunaiV",
"versions": [
{
"status": "affected",
"version": "2026.08"
}
]
},
{
"cpes": [
"cpe:2.3:a:zhijiantianya:ruoyi-vue-pro:*:*:*:*:*:*:*:*"
],
"modules": [
"Demo-order Payment Callback Handler"
],
"product": "ruoyi-vue-pro",
"vendor": "zhijiantianya",
"versions": [
{
"status": "affected",
"version": "2026.08"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "liuyulin (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T19:15:12.105Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409332 | YunaiV/zhijiantianya ruoyi-vue-pro Demo-order Payment Callback PayDemoOrderController.java updateDemoOrderPaid improper authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/409332"
},
{
"name": "VDB-409332 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409332/cti"
},
{
"name": "CVE-2026-97324 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-97324"
},
{
"name": "Submit #908275 | zhijiantianya ruoyi-vue-pro 2026.06 \u6743\u9650\u8bb8\u53ef",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/908275"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-24T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-24T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-24T13:39:47.000Z",
"value": "VulDB entry last update"
}
],
"title": "YunaiV/zhijiantianya ruoyi-vue-pro Demo-order Payment Callback PayDemoOrderController.java updateDemoOrderPaid improper authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-97324",
"datePublished": "2026-09-24T19:15:12.105Z",
"dateReserved": "2026-09-24T11:34:22.237Z",
"dateUpdated": "2026-09-24T19:15:12.105Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97245 (GCVE-0-2026-97245)
Vulnerability from cvelistv5 – Published: 2026-09-30 12:28 – Updated: 2026-09-30 13:27- CWE-266 - Incorrect Privilege Assignment
| URL | Tags |
|---|---|
| https://patchstack.com/database/wordpress/plugin/… | vdb-entry |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97245",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T13:08:09.066395Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:27:08.243Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "surecart",
"product": "SureCart",
"vendor": "SureCart",
"versions": [
{
"changes": [
{
"at": "4.7.3",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.7.2",
"status": "affected",
"version": "n/a",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Supakiad S. (m3ez) | Patchstack Bug Bounty Program"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Shop Worker Privilege Escalation in SureCart \u003c= 4.7.2 versions."
}
],
"value": "Shop Worker Privilege Escalation in SureCart \u003c= 4.7.2 versions."
}
],
"impacts": [
{
"capecId": "CAPEC-233",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-233 Privilege Escalation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "CWE-266 Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T12:28:03.954Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/surecart/vulnerability/wordpress-surecart-plugin-4-7-2-privilege-escalation-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress SureCart Plugin to the latest available version (at least 4.7.3)."
}
],
"value": "Update the WordPress SureCart Plugin to the latest available version (at least 4.7.3)."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "WordPress SureCart plugin \u003c= 4.7.2 - Privilege Escalation vulnerability",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2026-97245",
"datePublished": "2026-09-30T12:28:03.954Z",
"dateReserved": "2026-09-24T10:23:10.129Z",
"dateUpdated": "2026-09-30T13:27:08.243Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96882 (GCVE-0-2026-96882)
Vulnerability from cvelistv5 – Published: 2026-09-24 02:30 – Updated: 2026-09-29 02:43| URL | Tags |
|---|---|
| https://vuldb.com/vuln/409080 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/409080/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-96882 | third-party-advisory |
| https://vuldb.com/submit/906083 | third-party-advisory |
| https://github.com/hhhh333/CVE/blob/main/Lin-CMS-… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| TaleLin | lin-cms-spring-boot |
Affected:
0.2.0
Affected: 0.2.1 cpe:2.3:a:talelin:lin-cms-spring-boot:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96882",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T02:43:35.907412Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T02:43:48.384Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:talelin:lin-cms-spring-boot:*:*:*:*:*:*:*:*"
],
"modules": [
"book Endpoint"
],
"product": "lin-cms-spring-boot",
"vendor": "TaleLin",
"versions": [
{
"status": "affected",
"version": "0.2.0"
},
{
"status": "affected",
"version": "0.2.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "hhhha (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "Improper Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-266",
"description": "Incorrect Privilege Assignment",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T02:30:09.259Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409080 | TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/409080"
},
{
"name": "VDB-409080 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409080/cti"
},
{
"name": "CVE-2026-96882 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-96882"
},
{
"name": "Submit #906083 | https://github.com/logamee/lin-cms-spring-boot lin-cms 0.2.1 unauthorized access vulnerability",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/906083"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/hhhh333/CVE/blob/main/Lin-CMS-%E6%9C%AA%E6%8E%88%E6%9D%833.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-23T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-23T20:20:24.000Z",
"value": "VulDB entry last update"
}
],
"title": "TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-96882",
"datePublished": "2026-09-24T02:30:09.259Z",
"dateReserved": "2026-09-23T18:15:13.076Z",
"dateUpdated": "2026-09-29T02:43:48.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation MIT-1
Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Mitigation MIT-17
Strategy: Environment Hardening
Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.
No CAPEC attack patterns related to this CWE.