Improper Authentication in Open-Web-Analytics Controller by Open-Web-Analytics
CVE-2026-86810

6.9MEDIUM

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-86810?

A vulnerability has been identified in Open-Web-Analytics affecting versions up to 1.9.1. This vulnerability lies within the method checkCapabilityAndAuthenticateUser located in the Core/Controller.php file. Attackers can exploit this flaw to manipulate the authentication process, potentially allowing unauthorized access to the system. The vulnerability can be triggered remotely, raising significant security concerns for users of the affected product. To effectively address this issue, upgrading to version 1.10.0 is essential, as it includes a patch identified by the hash 6fc91c49eebdb8bfdfeed71cb50a5d97eac70f24.

Affected Version(s)

Open-Web-Analytics 1.9.0

Open-Web-Analytics 1.9.1

Open-Web-Analytics 1.10.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Customeres (VulDB User)
.