CVE-2026-85638
A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.30%
- CWE
- CWE-639, CWE-285
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- jofpin trape
Weakness type
Related vulnerabilities
- CVE-2026-88877 — Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
- CVE-2026-88865 — AVideo Missing Authorization via getRestream.json.php
- CVE-2026-80354 — Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
- CVE-2026-82582 — An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may...
- CVE-2026-84062 — BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through...
- CVE-2026-87997 — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
- CVE-2026-87994 — Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
- CVE-2026-47156 — MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator