Missing Authorization Vulnerability in sysPass by Caycon
CVE-2026-65710
Key Information:
Badges
What is CVE-2026-65710?
The vulnerability in sysPass version 3.2.11 arises from insufficient authorization checks during public link creation, enabling users with the PUBLICLINK_CREATE profile flag to exploit this flaw. An attacker can trigger unauthorized decryption of vault account passwords by invoking the saveCreateFromAccountAction endpoint. This bypasses AccountAcl checks, allowing access to arbitrary target accounts and facilitating the decryption of credentials with the session master key. Cleartext passwords are then stored in the PublicLink database, leading to the risk of subsequent unauthorized retrieval if the generated link hash is compromised.
Affected Version(s)
sysPass 0 <= 3.2.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
