CVE-2026-92752

HIGH CVSS 4.0: 8.7 EPSS 0.26%
Updated Sep 17, 2026
metasfresh
Parameter Value
CVSS 8.7 (HIGH)
Type CWE-639 (Authorization Bypass)
Vendor metasfresh
Public PoC No

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, and delete attachments and comments on records their role cannot access.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Weakness Type (CWE)