CVE-2026-69703
9.8 CRITICALpublic exploit availablePublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- Atlas-Livre has an improper access control vulnerability that allows unauthenticated attackers to bypass session-based authentication and execute admin actions, potentially leading to data deletion.
- Exploitability
- Exploitation is relatively straightforward as attackers can send raw HTTP requests to invoke admin actions without session state checks.
- Blast radius
- If exploited, this vulnerability could result in significant data loss or corruption, impacting the integrity and availability of the application's data.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected admin controller endpoints or restrict access to them to authenticated users only.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-48826PoC
- HIGHCVE-2026-70494PoC
- CRITICALCVE-2026-101077PoC
- CRITICALCVE-2026-102361PoC
- CRITICALCVE-2026-17635
- CRITICALCVE-2026-49994PoC
- CRITICALCVE-2026-53988PoC
- HIGHCVE-2026-61891PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.