Insecure Direct Object References in Fluent Boards Pro by Fluent Forms
CVE-2026-78278
5.3MEDIUM
What is CVE-2026-78278?
Fluent Boards Pro versions 2.0.11 and earlier have a vulnerability due to Subscriber Insecure Direct Object References (IDOR). This flaw allows unauthorized access to sensitive user data by exploiting the direct object references that are improperly secured. Attackers can potentially manipulate these references to view or modify data that should be restricted to specific users. It is crucial for users and administrators to update to protected versions and implement adequate access controls to mitigate this security issue.
Affected Version(s)
Fluent Boards Pro <= 2.0.11
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program