Authorization Flaw in Reconmap API Allows Unauthenticated Access
CVE-2026-77767

8.7HIGH

Key Information:

Vendor

Reconmap

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-77767?

A vulnerability in Reconmap's API exposes sensitive data due to an oversight in its authorization policies. The API's report preview action is improperly configured with the [AllowAnonymous] attribute, permitting unauthenticated users to access detailed project information, including sensitive client organization data. This allows attackers to enumerate through project IDs and reveal engagement details without requiring any form of user authentication or role-based access controls. Consequently, sensitive operational data, such as project names and associated client addresses, is unintentionally disclosed, posing a significant risk to the confidentiality of the information managed by Reconmap.

Affected Version(s)

reconmap 0 <= 3.2.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.