Mautic · Mautic · CVE-2026-9808
**Name of the Vulnerable Software and Affected Versions**
Mautic versions 7.0.0 through 7.1.1
**Description**
An authorization bypass exists in the API v2 endpoints (utilizing API Platform). Roles configured with owner-scope restrictions, such as `viewown` or `editown`, are not properly enforced. This allows authenticated API users with low privileges to bypass ownership-logic controls to access or modify resources belonging to other users, including reports, contacts, and companies, thereby bypassing structural tenant and privilege boundaries.
**Recommendations**
Update to version 7.1.2.
Temporarily revoke API credentials or narrow access permissions for users whose roles rely on owner-scope permission containment.