Missing Authorization Flaw in FluxBuilder MStore API by Patchstack
CVE-2026-57375
6.5MEDIUM
What is CVE-2026-57375?
The MStore API by FluxBuilder has a missing authorization vulnerability that arises from incorrectly configured access control security levels. This flaw can be exploited to gain unauthorized access to sensitive functionalities, posing a significant security risk. Users of MStore API versions up to 4.18.4 should be particularly vigilant and consider applying available patches to mitigate this issue.
Affected Version(s)
MStore API 0 <= 4.18.4