CVE-2026-9765
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
24/07/2026
Last modified:
24/07/2026
Description
Note: The CVE and blog post don&#39;t exist because we determined this is actually a cloud-only issue.<br />
<br />
Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. <br />
<br />
Broken access control can allow attackers to:<br />
Access resources only accessible to certain users, thus allowing unauthorized access to data<br />
Perform operations on behalf of other users, leading to account takeovers in the worst cases<br />
Attempt privilege escalation<br />
Attempt to take over an account
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH



