PT-2026-36213 · Owasp · Defectdojo
Noname1337
·
Published
2026-04-30
·
Updated
2026-05-01
·
CVE-2026-7510
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OWAP DefectDojo versions prior to 2.56.0
Description
An issue exists in the Benchmark, Engagement, Product, and Survey components where a manipulation can lead to a remote authorization bypass, allowing an attacker to circumvent access controls.
Recommendations
Update to version 2.56.0.
Exploit
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Defectdojo