CVE-2026-2676
Last modified
CVE-2026-2676 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.java of the component API Interface. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issue is the function preHandle of the file LoginInterceptor.java of the component API Interface. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-2676?
How severe is CVE-2026-2676?
How do I fix CVE-2026-2676?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26742PX4 Autopilot versions 1.12.x through 1.15.x contain a prote…8.1
- CVE-2026-26744A user enumeration vulnerability exists in FormaLMS 4.1.18 a…5.3
- CVE-2026-26745OpenSourcePOS 3.4.1 has a second order SQL Injection vulnera…5.3
- CVE-2026-26746OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vu…8.8
- CVE-2026-26747A Host Header Poisoning vulnerability exists in Monica 4.1.2…9.1
- CVE-2026-2675Missing Authentication for Critical Function vulnerability i…6.5
- CVE-2026-2677Reflected Cross-Site Scripting (XSS) on the A3factura web pl…6.1
- CVE-2026-2678Reflected Cross-Site Scripting (XSS) on the A3factura web pl…6.1
- CVE-2026-2679Reflected Cross-Site Scripting (XSS) on the A3factura web pl…6.1
- CVE-2026-26791GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a comm…9.8
- CVE-2026-26792GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multip…9.8
- CVE-2026-26793GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a comm…9.8
Are you affected by CVE-2026-2676?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
