CVE-2024-26310

MEDIUM

Archer Platform 6.8-6.14.0.2 - Authenticated Improper Access Control

Title source: llm
STIX 2.1

Description

Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access to API information that should only be accessible with extra privileges.

Scores

CVSS v3 4.3
EPSS 0.0039
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
archerirm/archer < 6.14.0.2
Published Feb 21, 2024
Tracked Since Feb 18, 2026