Improper Access Control in Archer by RSA
CVE-2022-26949
5.3MEDIUM
What is CVE-2022-26949?
Archer versions 6.x up to 6.9 SP2 P1 (6.9.2.1) are affected by an improper access control vulnerability concerning attachments. This vulnerability enables a remote authenticated malicious user to gain unauthorized access to files, which should only be accessible by users with elevated privileges. As a result, sensitive information may be exposed, highlighting the importance of applying security measures to safeguard affected systems.