CVE-2026-11877CWE-648

Missing Authorization Vulnerability in OpenText Access Manager

Medium · published June 24, 2026

CVSS v4.0
6.3
EPSS
0%
Percentile
22.9
In the wild
Unconfirmed
What it is

An unauthorized user can modify configuration through API

calls that affects the OpenText Access

Manager. This issue affects Access Manager before 5.1.3.

The record
Technical detail
CVSS v4.0
6.3 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS
0.00305 · 22.9th percentile
Weakness
CWE-648 · Incorrect Use of Privileged APIs
Published
2026-06-24T14:01Z
EPSS history
Timeline
  • 24 JUN 14:01Z
    Missing Authorization Vulnerability in OpenText Access Manager
    cvelistv5