Junglewise Threat Intelligence

CVE-2026-69703: Atlas-Livre improper access control in admin controllers

CVE-2026-69703 · Severity: critical · CVSS 9.8 · Published 2026-08-04

Executive brief

Atlas-Livre is an e-commerce platform for book sales and rentals. The application contains a critical flaw in its admin panel authentication that allows attackers to bypass login requirements and perform destructive actions like deleting records without any valid credentials. An attacker can exploit this by sending simple HTTP requests directly to admin functions, potentially causing unauthorized data loss and compromising the platform's integrity.

Technical details

The vulnerability is an improper access control flaw in the admin controllers located under Espace_admin/controleur/. The authentication guards use PHP header() redirects to enforce session-based access control, but the redirects are never followed by exit() or die() calls. This allows unauthenticated attackers to bypass the redirect by ignoring it and continue executing subsequent code, including database operations. Attackers can invoke destructive admin actions such as record deletion by sending GET requests with parameters like "supp" (delete). No authentication is required; the attack is network-accessible via raw HTTP requests.

Affected products

  • maximeAmini Atlas-Livre <unknown>

Timeline

  • 2026-07-31: disclosed
  • 2026-08-04: advisory: CVE-2026-69703 published

References