SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16309

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

EdoWEB versions prior to 780-g7 are vulnerable to an authorization bypass due to a user-controlled key, allowing unauthorized access to functionalities that are not properly constrained by Access Control Lists (ACLs). This vulnerability could lead to unauthorized actions within the application, potentially compromising sensitive data or system integrity. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized access.

CVE
CVE-2026-16309
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%

Original NVD Description

Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7.