CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.0. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-5652
Severity
CRITICAL
CVSS
9
EPSS
0.44%
Original NVD Description
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)