PT-2026-44542 · Linkace · Linkace

CVE-2026-45342

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions LinkAce versions prior to 2.5.6
Description An Insecure Direct Object Reference (IDOR) issue exists in the authorization policy layer, allowing authenticated users to modify resources owned by others, including links, lists, tags, and notes. This flaw affects both the web UI and the REST API. The root cause is located in the update() methods of the LinkPolicy, LinkListPolicy, TagPolicy, and NotePolicy models, which incorrectly grant access to any resource with non-private visibility regardless of ownership. Additionally, the AuthorizesUserApiActions::userCanUpdateModel() function in the API layer and bulk edit operations via BulkEditController are affected by the same logic error.
Recommendations Update to version 2.5.6.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45342
GHSA-CJ8F-H888-M57M

Affected Products

Linkace