CVE-2026-103534

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
6.3
MEDIUM
CVSS v2 Base Score
6.5
MEDIUM

Description

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded.

Published
October 1, 2026 4:18 AM
Last Modified
October 1, 2026 4:18 AM
Source
[email protected]

Weaknesses (CWE)

CWE-266 CWE-284

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.