CVE-2026-9765
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user
CVSS
7.1
Alto
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 24 jul 2026 · Última mod.: 24 jul 2026 · CWE-284
Sin historial EPSS suficiente todavía.
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account