Unauthenticated Access Control Issue in Legal Text Connector by IT-Recht Kanzlei
CVE-2026-66452

6.5MEDIUM

What is CVE-2026-66452?

The Legal Text Connector by IT-Recht Kanzlei versions up to 1.0.13 is susceptible to an unauthenticated broken access control vulnerability. This issue may allow unauthorized users to access restricted functionalities and potentially manipulate sensitive data or perform actions without proper authentication. Organizations using this plugin should review their security posture and apply necessary updates to mitigate potential risks.

Affected Version(s)

Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hhhai | Patchstack Bug Bounty Program
.