CVE-2026-6355 - Vulnerability Analysis
MediumCVSS: 6.5Last Updated: April 22, 2026
Web Application - Broken Access Control
Published: April 22, 2026Updated: April 22, 2026PoC AvailableRemote Exploitable
Overview
A web application contains a broken access control vulnerability caused by insecure direct object references, letting unauthorized users access and manipulate sensitive data across tenants, exploit requires no special privileges.
Severity & Score
Severity: Medium
CVSS Score: 6.5
Impact
Unauthorized users can access and modify sensitive tenant data, leading to data breaches and configuration changes.
Mitigation
Update to the latest version with proper access control checks.
Related Resources
Details
- CVE ID
- CVE-2026-6355
- Severity
- Medium
- CVSS Score
- 6.5
- Type
- broken_access_control
- Status
- unconfirmed
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N