PT-2026-67819 · Unknown · Atlas-Livre

·

CVE-2026-69703

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlas-Livre (affected versions not specified)
Description Improper access control exists within the admin controllers located under Espace admin/controleur/. Unauthenticated attackers can bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. This occurs because the PHP header() redirect function is not followed by an exit or die call, allowing subsequent code and database operations to execute regardless of the session state. Attackers can trigger destructive administrative actions, such as record deletion, by targeting controller endpoints using the supp GET parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69703

Affected Products

Atlas-Livre