Executive brief
The WriteUp Mobile App by Kurt Software Studio contains a security flaw that fails to properly restrict user permissions. This allows an authenticated user to access features or data they are not authorized to see or modify. An attacker could exploit this to compromise sensitive information or disrupt the application's operations.
Technical details
The WriteUp Mobile App (versions 1.3.0 through 04062026) suffers from improper access control (CWE-284) and missing authorization (CWE-862). The vulnerability exists because the application fails to properly enforce Access Control Lists (ACLs) on specific functionalities. An attacker with low-privileged network access can bypass these restrictions to perform actions or access data intended for higher-privileged users. This can lead to a full compromise of confidentiality, integrity, and availability within the context of the application.
Affected products
- Kurt Software Studio WriteUp Mobile App 1.3.0 through 04062026
Timeline
- 2026-06-04: disclosed
- 2026-06-04: advisory