Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-65709

Опубликовано: 24 июл. 2026
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.

EPSS

Процентиль: 13%
0.00223
Низкий

8.3 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.3
github
14 дней назад

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.

EPSS

Процентиль: 13%
0.00223
Низкий

8.3 High

CVSS3

Дефекты

CWE-639