PT-2026-64377 · Syspass · Syspass

·

CVE-2026-65710

·

Published

2026-07-24

·

Updated

2026-07-27

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions sysPass versions prior to 3.2.12
Description Authenticated users possessing the PUBLICLINK CREATE profile flag can trigger unauthorized decryption and persistent storage of any vault account password. This occurs due to missing AccountAcl checks during the public link creation process. An attacker can call the 'saveCreateFromAccountAction' endpoint, causing the getDataForLink() function in AccountService to load arbitrary target accounts without AccountFilterUser restrictions. This process decrypts credentials using the session master key and serializes cleartext passwords into the Vault storage within the PublicLink database row, which may allow unauthenticated retrieval if the resulting link hash is obtained.
Recommendations Update to a version newer than 3.2.11. Restrict the use of the PUBLICLINK CREATE profile flag for users until the update is applied.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65710

Affected Products

Syspass