All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-71384
CRITICALpublished 2026-08-11 17:19 UTC · 1 day ago · modified 2026-08-12 21:03 UTC
9.6
CVSS / 10
// description
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
// weaknesses (CWE)
- CWE-863