PT-2026-44542 · Linkace · Linkace
CVE-2026-45342
·
Published
2026-05-28
·
Updated
2026-07-21
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
LinkAce versions prior to 2.5.6
Description
An Insecure Direct Object Reference (IDOR) issue exists in the authorization policy layer, allowing authenticated users to modify resources owned by others, including links, lists, tags, and notes. This flaw affects both the web UI and the REST API. The root cause is located in the
update() methods of the LinkPolicy, LinkListPolicy, TagPolicy, and NotePolicy models, which incorrectly grant access to any resource with non-private visibility regardless of ownership. Additionally, the AuthorizesUserApiActions::userCanUpdateModel() function in the API layer and bulk edit operations via BulkEditController are affected by the same logic error.Recommendations
Update to version 2.5.6.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linkace