SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65476

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

Civi versions up to 2.2.4 are susceptible to unauthenticated broken access control vulnerabilities, which could allow unauthorized users to access sensitive data or perform actions typically restricted to authenticated users. Organizations utilizing affected versions should prioritize remediation to mitigate potential data exposure and unauthorized system manipulation.

CVE
CVE-2026-65476
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.