LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6355 - Vulnerability Analysis

MediumCVSS: 6.5

Last Updated: April 22, 2026

Web Application - Broken Access Control

Published: April 22, 2026Updated: April 22, 2026PoC AvailableRemote Exploitable

Overview

A web application contains a broken access control vulnerability caused by insecure direct object references, letting unauthorized users access and manipulate sensitive data across tenants, exploit requires no special privileges.

Severity & Score

Severity: Medium
CVSS Score: 6.5

Impact

Unauthorized users can access and modify sensitive tenant data, leading to data breaches and configuration changes.

Mitigation

Update to the latest version with proper access control checks.

Details

CVE ID
CVE-2026-6355
Severity
Medium
CVSS Score
6.5
Type
broken_access_control
Status
unconfirmed

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N