Executive brief
A security flaw exists in the user management system of the affected products. An attacker with a standard user account can bypass security checks to delete other user accounts, including those belonging to administrators. This could lead to a significant disruption of service and loss of administrative control over the system.
Technical details
The vulnerability is classified as Incorrect Authorization (CWE-863) within the user account deletion functionality. The root cause is a failure to sufficiently verify the permissions of the requesting user against the target account being deleted. An attacker must be authenticated with low-level privileges and have network access to the application. By sending a crafted request, the attacker can delete arbitrary user accounts, including administrative accounts, resulting in a high impact on system integrity and availability. No user interaction is required for exploitation.
Affected products
- Unknown Vendor Affected Products
Timeline
- 2026-05-26: disclosed: Initial publication of the CVE record.