PT-2026-64376 · Syspass · Syspass

·

CVE-2026-65709

·

Published

2026-07-24

·

Updated

2026-07-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions sysPass versions prior to 3.2.12
Description A missing object-level authorization issue exists in the JSON-RPC API. This allows holders of API tokens to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault, bypassing per-account access controls. The flaw occurs because the AccountController methods viewAction(), editAction(), deleteAction(), and editPassAction() can be invoked without the required AccountFilterUser checks, enabling the modification or deletion of accounts outside the permissions assigned to the token.
Recommendations Update sysPass to a version newer than 3.2.11.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65709

Affected Products

Syspass