CVE-2026-11369

The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the requesting user has access to the object identified by the relatedObjectId. This Insecure Direct Object Reference (IDOR) vulnerability allows any authenticated user to read and write comments on any process across all business units by supplying an arbitrary object GUID.
CVSS

No CVSS.

Configurations

No configuration.

History

05 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-05 14:16

Updated : 2026-06-17 10:13


NVD link : CVE-2026-11369

Mitre link : CVE-2026-11369

CVE.ORG link : CVE-2026-11369


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key