CVE-2026-77142EPSS p32.5%
CVE-2026-77142CVE-2026-77142
Description
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it.
Scoring
| EPSS | 0.41% probability of exploitation · percentile 32.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |