CVE-2026-10285

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

22 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en la gestión de proyectos DevaslanPHP hasta la versión 2.0.0-beta1. Afectada por este problema es la función KanbanScrumHelper::recordUpdated del archivo app/Helpers/KanbanScrumHelper.php del componente Gestor de Tickets. La manipulación conduce a una autorización incorrecta. El ataque es posible de llevar a cabo de forma remota. El proyecto fue informado del problema con antelación a través de un informe de problema, pero aún no ha respondido.

01 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 21:16

Updated : 2026-07-22 08:10


NVD link : CVE-2026-10285

Mitre link : CVE-2026-10285

CVE.ORG link : CVE-2026-10285


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization