CVE-2026-57869CWE-1241CWE-639

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents…

High · published July 7, 2026

CVSS v4.0
7.1
EPSS
0%
Percentile
29.5
In the wild
Unconfirmed
What it is

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization.

This issue affects MicroRealEstate: through 1.0.0-alpha3.

The record
Technical detail
CVSS v4.0
7.1 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00364 · 29.5th percentile
Weaknesses
CWE-1241 · Use of Predictable Algorithm in Random Number Generator; CWE-639 · Authorization Bypass Through User-Controlled Key
Published
2026-07-07T05:24Z
EPSS history
Timeline
  • 07 JUL 05:24Z
    Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents…
    cvelistv5