Authorization Flaw in Reconmap API Allows Unauthenticated Access
CVE-2026-77767
8.7HIGH
What is CVE-2026-77767?
A vulnerability in Reconmap's API exposes sensitive data due to an oversight in its authorization policies. The API's report preview action is improperly configured with the [AllowAnonymous] attribute, permitting unauthenticated users to access detailed project information, including sensitive client organization data. This allows attackers to enumerate through project IDs and reveal engagement details without requiring any form of user authentication or role-based access controls. Consequently, sensitive operational data, such as project names and associated client addresses, is unintentionally disclosed, posing a significant risk to the confidentiality of the information managed by Reconmap.
Affected Version(s)
reconmap 0 <= 3.2.2
