rootpwn

medium · CVSS v3 6.5

CVE-2026-97280

The CVE-2026-97280 flaw is a missing authorization issue in Review Schema 3.1.0 that allows attackers to bypass access controls and manipula

Overview

The CVE-2026-97280 flaw is a missing authorization issue in Review Schema 3.1.0 that allows attackers to bypass access controls and manipulate or view review data. It is publicly disclosed and rated medium severity with a CVSS v3 score of 6.5. The vulnerability could lead to unauthorized data exposure or tampering if not addressed.

Description

Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0.

Impact

Unauthorized users can read, modify, or delete review records, compromising confidentiality, integrity, and potentially availability of the review system. Administrators and end‑users of the affected application are directly impacted.

Remediation

Apply the vendor‑issued patch for Review Schema 3.1.0 or upgrade to the latest release. Verify that role‑based access controls are correctly configured and restrict permissions to the minimum required. Enable logging of all review‑related actions and regularly audit the logs for suspicious activity.

Risk context

The vulnerability is rated medium severity (CVSS 6.5) with no EPSS data available, indicating a moderate risk that should be mitigated promptly but does not represent an immediate critical threat.

Affected products

  • Review Schema 3.1.0

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.5
CVSS v4
—
EPSS
—

missing-authorization access-control review-schema medium-severity data-exposure

← All CVEs