CVE-2026-65504
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVSS
7.5
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 6 ago 2026 · Última mod.: 6 ago 2026 · CWE-862
Sin historial EPSS suficiente todavía.
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-182777.1 ALT—
———Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path7hCVE-2026-182764.3 MED—
———Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check7hCVE-2026-667127.5 ALT—
———Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.7hCVE-2026-667088.2 ALT—
———Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.8hCVE-2026-667015.3 MED—
———Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.8hCVE-2026-666995.3 MED—
———Custom role Broken Access Control in Dokan <= 5.0.10 versions.8h