CVE-2026-57869CWE-1241CWE-639
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents…
High · published July 7, 2026
What it is
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization.
This issue affects MicroRealEstate: through 1.0.0-alpha3.
The record
Technical detail
- CVSS v4.0
- 7.1 · HIGH
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS
- 0.00364 · 29.5th percentile
- Weaknesses
- CWE-1241 · Use of Predictable Algorithm in Random Number Generator; CWE-639 · Authorization Bypass Through User-Controlled Key
- Published
- 2026-07-07T05:24Z
EPSS history
Timeline