AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-28155

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to exploit Insecure Direct Object References (IDOR) in Do Lasso versions up to and including 358, potentially leading to unauthorized access to sensitive resources. Organizations using these versions should prioritize remediation to mitigate the risk of data exposure and unauthorized actions. This is particularly critical for those handling sensitive or personal information.

CVE
CVE-2026-28155
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.