Junglewise Threat Intelligence

CVE-2026-57870: MicroRealEstate broken access control in Templates API

CVE-2026-57870 · Severity: info · CVSS 5.3 · Published 2026-07-07

Technologies: Camel Aissani MicroRealEstate. Vendors: Camel Aissani.

Executive brief

MicroRealEstate, an open-source platform for managing rental properties and real estate, contains a security flaw in how it handles document templates. An authorized user from one organization can access and download document templates belonging to other organizations on the same platform. This could lead to the exposure of proprietary business documents, lease structures, or sensitive organizational templates to unauthorized parties.

Technical details

A Broken Object Level Authorization (BOLA) vulnerability exists in the Templates API of MicroRealEstate through version 1.0.0-alpha3. The application fails to validate whether the requesting user has the appropriate permissions or organizational affiliation to access a specific template resource. By manipulating template identifiers in API requests, an authenticated attacker can bypass intended isolation boundaries to retrieve document templates belonging to any other organization registered on the platform. As of the advisory date, no official patch has been confirmed.

Affected products

  • Camel Aissani MicroRealEstate through 1.0.0-alpha3

Timeline

  • 2026-07-07: disclosed: Vulnerability disclosed by The Missing Link Security
  • 2026-07-07: advisory

References

Related threats