PT-2026-6794 · Deepaudit · Deepaudit

Ez-Lbz

·

Publicado

2026-02-06

·

Atualizado

2026-02-28

·

CVE-2026-25729

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DeepAudit versions prior to 3.0.5
Description An improper access control issue exists in DeepAudit versions 3.0.4 and earlier. The /api/v1/users/ API endpoint allows any authenticated user to enumerate all users within the system. This allows retrieval of sensitive information such as email addresses, phone numbers, full names, and role information. The vulnerable parameter is not specified.
Recommendations Update DeepAudit to version 3.0.5 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25729
GHSA-VMMM-48W2-Q56Q

Produtos afetados

Deepaudit