Authorization Bypass Vulnerability in HYPR Server Affects User Controls
CVE-2026-2414

5.6MEDIUM

Key Information:

Vendor

Hypr

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2026-2414?

A serious security flaw in HYPR Server allows unauthorized access due to an authorization bypass through a user-controlled key. This vulnerability could enable attackers to elevate privileges and gain access to sensitive resources, posing significant risks to system integrity and confidentiality. Affected versions include those prior to 10.7.2, specifically from version 9.5.2 and earlier, highlighting the need for immediate remediation and patching to safeguard against potential exploitation.

Affected Version(s)

Server 9.5.2 < 10.7.2

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.