PT-2026-68362 · Open Library Foundation · Vufind

CVE-2026-52466

·

Published

2026-08-05

·

Updated

2026-08-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Library Foundation VuFind version 11.0.3 Open Library Foundation VuFind version 4.1
Description Incorrect access control exists where the application fails to stop processing incoming requests within the validateAccessPermission() function of VuFindControllerAbstractBase. Although the system returns a response indicating that access was denied, the requested function is still executed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52466

Affected Products

Vufind