CVE-2026-71242

Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of one company can read, edit, or delete another company's notes by ID.
References
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 11:16

Updated : 2026-08-26 17:13


NVD link : CVE-2026-71242

Mitre link : CVE-2026-71242

CVE.ORG link : CVE-2026-71242


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key