CVE-2026-46721
Last modified
CVE-2026-46721 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-46721?
How severe is CVE-2026-46721?
How do I fix CVE-2026-46721?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-46716Nezha Monitoring is a self-hostable, lightweight, servers an…9.9
- CVE-2026-46717Nezha Monitoring is a self-hostable, lightweight, servers an…7.7
- CVE-2026-46718Use of Externally-Controlled Input to Select Classes or Code…6.5
- CVE-2026-46719Net::Statsd::Lite versions before 0.9.0 for Perl allowed met…6.5
- CVE-2026-4672GitLab has remediated an issue in GitLab CE/EE affecting all…4.3
- CVE-2026-46720Net::Statsd::Tiny versions before 0.3.8 for Perl allowed met…8.2
- CVE-2026-46722The OOXML parsing of the file indexer does not disable exter…5.9
- CVE-2026-46723The additional_tables configuration of the page and tt_conte…5.9
- CVE-2026-46724The file indexer does not normalize the configured directory…5.9
- CVE-2026-46725The extension passes an attacker-controlled cookie directly …9.2
- CVE-2026-46726Improper Input Validation, Exposure of Sensitive Information…7.5
- CVE-2026-46727An issue was discovered in Ruby 4 before 4.0.5. A race condi…8.1
Are you affected by CVE-2026-46721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
