← Back to search

CVE-2026-69703

9.8 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
Atlas-Livre has an improper access control vulnerability that allows unauthenticated attackers to bypass session-based authentication and execute admin actions, potentially leading to data deletion.
Exploitability
Exploitation is relatively straightforward as attackers can send raw HTTP requests to invoke admin actions without session state checks.
Blast radius
If exploited, this vulnerability could result in significant data loss or corruption, impacting the integrity and availability of the application's data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected admin controller endpoints or restrict access to them to authenticated users only.
auth-bypasswebdata-loss

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-306

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.