Executive brief
Pointsharp ID Server, an identity management solution used for secure authentication, contains a security flaw in its access control mechanisms. An attacker who is already a registered user on the system could exploit this to access or modify data belonging to other users. This could lead to unauthorized data exposure or the compromise of other user accounts within the organization.
Technical details
Pointsharp ID Server versions prior to 9.0.0 are vulnerable to an authorization bypass (CWE-639: Authorization Bypass Through User-Controlled Key). The flaw exists in the access control logic, where the application fails to properly validate that an authenticated user has permission to access resources associated with a specific identifier or key. An attacker with low-level authenticated access can manipulate these identifiers to perform horizontal privilege escalation, gaining access to data or functionality belonging to other users of the same privilege level. The vulnerability is network-reachable and requires valid user credentials but no user interaction. Pointsharp has addressed this issue in version 9.0.0.
Affected products
- Pointsharp ID Server versions up to (excluding) 9.0.0
Timeline
- 2026-03-06: patched: Vendor released advisory PSA-2026-001 and version 9.0.0.
- 2026-03-13: disclosed: CVE-2026-3999 published to NVD.