LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-0562 - Vulnerability Analysis

HighCVSS: 8.3

Last Updated: March 29, 2026

parisneo lollms - Broken Access Control

Published: March 29, 2026Updated: March 29, 2026Remote Exploitable

Overview

parisneo/lollms <= 2.2.0 contains an insecure direct object reference caused by missing authorization checks in respond_request() in backend/routers/friends.py, letting authenticated users accept or reject others' friend requests, exploit requires user authentication.

Severity & Score

Severity: High
CVSS Score: 8.3
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated users can manipulate friend requests of others, leading to unauthorized access and privacy violations.

Mitigation

Update to version 2.2.0 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 29, 2026

🟠 CVE-2026-0562 - High (8.3) A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not impleme... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-0562/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 29, 2026

🟠 CVE-2026-0562 - High (8.3) A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not impleme... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-0562/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-0562
Severity
High
CVSS Score
8.3
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-863

CVSS Metrics

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

EPSS Score

0.0%Probability of exploitation in the next 30 days