CVE-2026-81793
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- CWE
- CWE-862
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- Dimitri Grassi Salon booking system
Weakness type
Related vulnerabilities
- CVE-2026-11446 — Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization
- CVE-2026-11496 — Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure
- CVE-2026-18121 — Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}).
- CVE-2026-81211 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-89054 — OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
- CVE-2026-88959 — Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
- CVE-2026-4129 — Improper Access Controls in NI SystemLink
- CVE-2026-88898 — AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint