AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-57869

HIGH · CVSS 7.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

MicroRealEstate versions up to 1.0.0-alpha3 are vulnerable due to broken object-level access controls and predictable random ID generation, enabling unauthorized access to sensitive documents uploaded by landlords or tenants. This flaw poses a significant risk of data exposure, making it critical for organizations using this software to prioritize remediation efforts to protect user privacy and maintain compliance.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57869
Severity
HIGH
CVSS
7.1
EPSS
0.21%

Original NVD Description

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.