CVE-2026-36453
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
- EPSS probability
- 0.16%
- CWE
- CWE-425
- Published
- 2026-09-13
- Last modified
- 2026-09-14
Affected products
- Rhymix Rhymix
Weakness type
Related vulnerabilities
- CVE-2024-45195 — Apache OFBiz: Confused controller-view authorization logic (forced browsing)
- CVE-2025-26689 — Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker
- CVE-2024-24592 — Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote atta
- CVE-2024-0204 — Authentication Bypass in GoAnywhere MFT
- CVE-2025-55736 — flaskBlog allows arbitrary privilege escalation
- CVE-2025-1542 — Improper permission control in OXARI ServiceDesk
- CVE-2024-6188 — Parsec Automation TrackSYS pagedefinition direct request
- CVE-2021-34588 — Bender Charge Controller: Unprotected data export