PT-2026-34013 · Unknown · Crafty Controller

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-5652

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Crafty Controller (affected versions not specified)
Description An insecure direct object reference (IDOR) issue in the Users API component allows a remote, authenticated attacker to perform user modification actions. This occurs due to improper API permissions validation, enabling an authenticated user to escalate privileges to administrator by manipulating user IDs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5652

Affected Products

Crafty Controller