9
CVE-2026-5652
- EPSS 0.44%
- Veröffentlicht 21.04.2026 16:33:56
- Zuletzt bearbeitet 27.04.2026 19:47:08
- Quelle cve@gitlab.com
- CVE-Watchlists
- Unerledigt
Authorization Bypass Through User-Controlled Key in Crafty Controller
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Craftycontrol ≫ Crafty Controller Version < 4.10.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.44% | 0.349 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@gitlab.com | 9 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://gitlab.com/crafty-controller/crafty-4/-/work_items/705