Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-9765

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-284 Control de acceso incorrecto
Fecha de publicación:
24/07/2026
Última modificación:
24/07/2026

Descripción

*** Pendiente de traducción *** Note: The CVE and blog post don&amp;#39;t exist because we determined this is actually a cloud-only issue.<br /> <br /> Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. <br /> <br /> Broken access control can allow attackers to:<br /> Access resources only accessible to certain users, thus allowing unauthorized access to data<br /> Perform operations on behalf of other users, leading to account takeovers in the worst cases<br /> Attempt privilege escalation<br /> Attempt to take over an account

Referencias a soluciones, herramientas e información