CVE-2026-52466
Last modified
CVE-2026-52466 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function.
Description
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-52466?
How severe is CVE-2026-52466?
How do I fix CVE-2026-52466?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5242Improper neutralization of formula elements in a CSV file vu…8.8
- CVE-2026-5243The The Plus Addons for Elementor – Addons for Elementor, Pa…6.4
- CVE-2026-52439An issue in xiandafu beetl 3.20.2 allows a remote attacker t…9.8
- CVE-2026-5244A vulnerability has been found in Cesanta Mongoose up to 7.2…9.8
- CVE-2026-5245A vulnerability was found in Cesanta Mongoose up to 7.20. Th…8.1
- CVE-2026-5246A vulnerability was determined in Cesanta Mongoose up to 7.2…8.1
- CVE-2026-52469SQL injection vulnerability in Crocus v.1.3.44 allows a remo…9.8
- CVE-2026-5247The Schedule Post Changes With PublishPress Future plugin fo…5.5
- CVE-2026-52470SQL injection vulnerability in Crocus v.1.3.44 allows a remo…9.8
- CVE-2026-52472SQL injection vulnerability in Wgcloud 3.6.4 allows a remote…9.8
- CVE-2026-52474An issue in aiflowy <= 2.1.2 allows a remote attacker to obt…7.5
- CVE-2026-52475Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allow…6.1
Are you affected by CVE-2026-52466?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
