PT-2026-48637 · Cerebrate · Cerebrate

·

CVE-2026-53911

·

Published

2026-06-11

·

Updated

2026-06-11

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Cerebrate versions prior to 1.37
Description An authenticated attacker can perform unauthorized modification of records by supplying the id primary key field through request input during CRUD edit operations and specific custom entity patching flows. In entities where id is not explicitly marked as inaccessible, a crafted request containing the id of another record causes the save operation to update that unrelated record instead of the one identified by the route parameter. This issue affects entity types with permissive mass-assignment defaults, such as User, Role, UserSetting, LocalTool, PermissionLimitation, and EnumerationCollection. Because the UserSettings edit functionality is accessible to any authenticated user, this can lead to unauthorized record modifications depending on the writable fields and the endpoint used.
Recommendations Update to version 1.37.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53911

Affected Products

Cerebrate