CVE-2026-5251
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.24%
- CWE
- CWE-915, CWE-913
- Published
- 2026-04-01
- Last modified
- 2026-04-01
Affected products
- z-9527 admin
- z-9527 admin
Weakness type
Related vulnerabilities
- CVE-2026-85408 — Eleveo Quality Management Conversation events dynamically-determined object attributes
- CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-83557 — jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base types
- CVE-2026-78038 — Job argument injection via :args overrides primary_key and tenant in AshOban
- CVE-2026-77144 — Broken Access Control in extension "Events 2" (events2)
- CVE-2026-71504 — Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset
- CVE-2026-78416 — Authenticated RCE via `condition.config` JSON cleanse bypass
- CVE-2026-62315 — Frappe: Mass assignment via set_value