CVE-2026-52466 - VuFind Incorrect Access Control Vulnerability
CVE ID :CVE-2026-52466
Published : Aug. 6, 2026, 12:16 a.m. | 38 minutes ago
Description :Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 6, 2026, 12:16 a.m. | 38 minutes ago
Description :Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...