PT-2026-78913 · Zoo · Zoo

CVE-2026-76610

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zoo versions prior to 4.1.65
Description The comment controller endpoint lacks Access Control List (ACL) checks, which are security permissions that define which users can access specific resources. This flaw allows unauthenticated users to perform unauthorized tag modifications.
Recommendations Update Zoo to version 4.1.65 or later.

Fix

CSRF

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76610

Affected Products

Zoo