medium · CVSS v3 6.5
CVE-2026-97280
The CVE-2026-97280 flaw is a missing authorization issue in Review Schema 3.1.0 that allows attackers to bypass access controls and manipula
Overview
The CVE-2026-97280 flaw is a missing authorization issue in Review Schema 3.1.0 that allows attackers to bypass access controls and manipulate or view review data. It is publicly disclosed and rated medium severity with a CVSS v3 score of 6.5. The vulnerability could lead to unauthorized data exposure or tampering if not addressed.
Description
Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0.
Impact
Unauthorized users can read, modify, or delete review records, compromising confidentiality, integrity, and potentially availability of the review system. Administrators and end‑users of the affected application are directly impacted.
Remediation
Apply the vendor‑issued patch for Review Schema 3.1.0 or upgrade to the latest release. Verify that role‑based access controls are correctly configured and restrict permissions to the minimum required. Enable logging of all review‑related actions and regularly audit the logs for suspicious activity.
Risk context
The vulnerability is rated medium severity (CVSS 6.5) with no EPSS data available, indicating a moderate risk that should be mitigated promptly but does not represent an immediate critical threat.
Affected products
- Review Schema 3.1.0
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —