PT-2026-85228 · Unopim · Unopim

·

CVE-2026-85395

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions UnoPim versions prior to 2.1.3
Description Insufficient authorization validation in the Bouncer middleware occurs because the integration store, update, and key-generation routes are missing from the Access Control List (ACL) map. This allows users with minimal administrative privileges to bypass permission checks, create OAuth API integrations, and mint client credentials to escalate their permissions.
Recommendations Update to version 2.1.3 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85395

Affected Products

Unopim