Improper Access Control in Atlas-Livre Admin Controllers
CVE-2026-69703

9.3CRITICAL

Key Information:

Vendor
CVE Published:
4 August 2026

What is CVE-2026-69703?

Atlas-Livre exhibits an improper access control vulnerability within its admin controllers located under Espace_admin/controleur/. This flaw permits unauthenticated attackers to circumvent session-based authentication protections through the manipulation of raw HTTP requests that do not comply with the necessary redirects. Specifically, by targeting vulnerable controller endpoints with specific GET parameters, attackers can invoke critical administrative functions such as record deletion. The absence of an exit or die call following the PHP header() redirect results in the execution of subsequent code, including database manipulation, independent of the user’s session state.

Affected Version(s)

Atals-Livre 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Jain
.