SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73381

CRITICAL · CVSS 9.1 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to exploit broken authentication mechanisms in Supsystic versions prior to 1.13.0, potentially leading to unauthorized access and manipulation of user accounts. Organizations using affected versions should prioritize patching this critical flaw to mitigate the risk of data breaches and account takeovers. Immediate action is essential for any entity utilizing Supsystic plugins to ensure the security of their web applications.

CVE
CVE-2026-73381
Severity
CRITICAL
CVSS
9.1
EPSS
0.51%

Original NVD Description

Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.