Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.
References
| Link | Resource |
|---|---|
| https://vufind.org/wiki/security:cve-2026-52466 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-06 00:16
Updated : 2026-09-09 16:04
NVD link : CVE-2026-52466
Mitre link : CVE-2026-52466
CVE.ORG link : CVE-2026-52466
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
