PT-2026-33548 · Movary · Movary

Kitu232

·

Published

2026-04-18

·

Updated

2026-04-18

·

CVE-2026-40350

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Movary versions prior to 0.71.1
Description An authenticated user can access user-management endpoints, specifically '/settings/users', to enumerate all users and create a new administrator account. This occurs because route definitions lack admin-only middleware and the controller-level authorization check employs a broken boolean condition, allowing any user with a valid web session cookie to access restricted administrative functionality.
Recommendations Update to version 0.71.1.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-40350

Affected Products

Movary