Missing Object-Level Authorization in sysPass JSON-RPC API
CVE-2026-65709
Key Information:
Badges
What is CVE-2026-65709?
The sysPass version 3.2.11 vulnerability arises from a missing object-level authorization in its JSON-RPC API. This flaw permits API token holders to improperly enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without necessary per-account access controls. Attackers can utilize AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without adequate AccountFilterUser checks, potentially allowing modifications or deletions of user accounts beyond their intended permissions.
Affected Version(s)
sysPass 0 <= 3.2.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
