AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-57867

HIGH · CVSS 8.8 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

MicroRealEstate is vulnerable due to inadequate token state management, allowing attackers to bypass authentication mechanisms. This flaw enables adversaries to brute-force One-Time Passwords (OTP), potentially granting them unauthorized access to any user account. Organizations using MicroRealEstate versions up to 1.0.0-alpha3 should prioritize addressing this vulnerability to protect user accounts from unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57867
Severity
HIGH
CVSS
8.8
EPSS
0.37%

Original NVD Description

MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.