rootpwn

high · CVSS v3 8.3 · CVSS v4 8.7

CVE-2026-92752

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in …

Description

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, and delete attachments and comments on records their role cannot access.

Scores

Severity
high
CVSS v2
8.7
CVSS v3
8.3
CVSS v4
8.7
EPSS

← All CVEs