CyberRota
← Ana sayfaya dön

CVE-2026-29204

CRITICAL · CVSS 9.1 EPSS %0.04

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-12T18:16:51.030 · Çekilme zamanı: 2026-06-09T06:00:53.579069+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-29204
Severity
CRITICAL
CVSS
9.1
EPSS
%0.04

Orijinal NVD Açıklaması

Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized access to the victim's account.