Junglewise Threat Intelligence

CVE-2026-38807: kvf-admin IDOR privilege escalation in UserController

CVE-2026-38807 · Severity: info · CVSS 8.8 · Published 2026-05-27

Executive brief

kvf-admin is an administrative management framework. A security flaw in the user profile update feature allows any logged-in user to modify the account details of other users, including administrators. An attacker could use this to take over administrative accounts, lock out legitimate users, or gain full control over the management system.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `updateInfo` method of `UserController.java` in kvf-admin v1.0.0. The application fails to validate whether the `id` parameter provided in the POST request matches the identity of the currently authenticated user. Furthermore, the endpoint lacks proper permission annotations or object-level access control. By manipulating the `id` field in a profile update request (e.g., changing it to '1' for the admin user), a low-privileged attacker can modify sensitive account fields such as usernames and contact information, leading to full account takeover and vertical privilege escalation.

Affected products

  • kalvinGit kvf-admin 1.0.0

Timeline

  • 2026-03-27: disclosed: Vulnerability details shared on GitHub issues
  • 2026-05-27: advisory: CVE published by NIST/MITRE

References