PT-2026-90979 · Jaygajera17 · E-Commerce-Project-Springboot

·

CVE-2026-90598

·

Published

2026-09-13

·

Updated

2026-09-13

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions jaygajera17 E-commerce-project-springBoot versions up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2
Description An authorization bypass can be triggered remotely by manipulating the userid argument within the updateUser() function of the UserController.java file.
Recommendations As a temporary workaround, restrict access to the updateUser() function until the pending pull request is accepted and merged.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90598

Affected Products

E-Commerce-Project-Springboot