CRITICAL🇵🇱 Wersja polska

CVE-2026-5652

CVSS 9.0v3.1pub. 2026-04-21upd. 2026-04-27

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.

🤖 AI Analysis
How it works

The vulnerability stems from improper permission validation in the user management API. An attacker with an account in the system can send API requests directly referencing objects (user accounts) other than those they should have access to. The lack of proper server-side authorization control allows circumventing restrictions resulting from the assigned role and performing modification operations on any user account.

Impact

An attacker can modify data of other system users, including potentially administrator accounts, which may lead to system takeover, privilege escalation, or violation of integrity and confidentiality of managed resources.

Mitigation & patch

Apply patches available from the vendor according to the references (https://gitlab.com/crafty-controller/crafty-4/-/work_items/705). It is recommended to restrict access to the administrative panel exclusively to trusted networks and to regularly review user account permissions until the patch is implemented.

Who is affected

Craftycontrol Crafty Controller — versions specified in the vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
  • Craftycontrol Crafty Controller

    APP
    Craftycontrol
    < 4.10.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
IDOR
CWE
References

Related vulnerabilities

CVE-2026-13716CRITICAL9.1same product

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated att...

CVE-2026-0963CRITICAL9.9PL ✓same product

Path Traversal umożliwiający RCE w Crafty Controller (File Operations API)

CVE-2025-14700CRITICAL9.9PL ✓same product

RCE przez Server Side Template Injection w Crafty Controller (Webhook Template)

CVE-2026-0805HIGH8.2same product

An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remo...

CVE-2025-14701HIGH7.1same product

An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unaut...