CVE-2026-65485
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVSS
5.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-862
Not enough EPSS history yet.
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-477556.5 MED—
———ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal with an arbitrary `credential_id`. The endpoint does not enforce client scoping or object-level authorization before loading and decrypting the credential record. Version 26.05 fixes the issue.17mCVE-2026-659168.1 HIG—
———CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants.39mCVE-2026-658958.5 HIG—
——0Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.3hCVE-2026-655374.3 MED—
——0Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.2hCVE-2026-655314.8 MED—
——0Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.2hCVE-2026-655304.3 MED—
——0Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.3h