CVE-2026-38807

Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserController.java component
Configurations

No configuration.

History

28 May 2026, 16:16

Type Values Removed Values Added
CWE CWE-639
References () https://github.com/cagexunxi/CVE/issues/1 - () https://github.com/cagexunxi/CVE/issues/1 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

27 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 18:16

Updated : 2026-05-28 16:16


NVD link : CVE-2026-38807

Mitre link : CVE-2026-38807

CVE.ORG link : CVE-2026-38807


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key