PT-2026-95547 · Unknown · Lubelogger

CVE-2026-62279

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions LubeLogger versions prior to 1.6.8
Description An authenticated user can exploit a missing authorization check in the DuplicateRecordsToOtherVehicles endpoint. While the system verifies the destination vehicles, it fails to call the UserCanEditVehicle() function for each existingRecord.VehicleId when fetching source records in Controllers/VehicleController.cs. This allows an attacker to copy service, collision, upgrade, fuel, tax, supply, note, odometer, reminder, plan, inspection, and equipment records belonging to other users into a vehicle they control, exposing record contents and attachment paths.
Recommendations Update to version 1.6.8.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62279
GHSA-3R34-MX83-Q67R

Affected Products

Lubelogger