PT-2026-64376 · Syspass · Syspass
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
sysPass versions prior to 3.2.12
Description
A missing object-level authorization issue exists in the JSON-RPC API. This allows holders of API tokens to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault, bypassing per-account access controls. The flaw occurs because the
AccountController methods viewAction(), editAction(), deleteAction(), and editPassAction() can be invoked without the required AccountFilterUser checks, enabling the modification or deletion of accounts outside the permissions assigned to the token.Recommendations
Update sysPass to a version newer than 3.2.11.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syspass