An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the information of other registered users. Successful exploitation of this vulnerability allows an authenticated user to modify other users' information, such as their email address, and request a new password via the '/webconnect/#/forgotPassword' endpoint. This could lead to complete account takeover.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-mphrxs-minerva | Third Party Advisory |
Configurations
History
05 May 2026, 14:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-mphrxs-minerva - Third Party Advisory | |
| First Time |
Agilonhealth
Agilonhealth minerva |
|
| CPE | cpe:2.3:a:agilonhealth:minerva:3.6.0:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
28 Apr 2026, 13:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-28 13:19
Updated : 2026-06-17 10:59
NVD link : CVE-2026-5779
Mitre link : CVE-2026-5779
CVE.ORG link : CVE-2026-5779
JSON object : View
Products Affected
agilonhealth
- minerva
CWE
CWE-284
Improper Access Control
