SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-9765

HIGH · CVSS 7.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

This vulnerability allows attackers to bypass access control mechanisms in a web application, granting them unauthorized access to sensitive resources and potentially enabling account takeovers or privilege escalation. Organizations utilizing cloud-based applications should prioritize addressing this issue to safeguard against unauthorized data access and protect user accounts from compromise. Immediate action is recommended for those managing applications that handle sensitive user information or critical business operations.

CVE
CVE-2026-9765
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account