CVE-2025-26523

HIGH

RupeeWeb < 66.9 - Authenticated Incorrect Privilege Assignment via API Endpoints

Title source: llm
STIX 2.1

Description

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other user accounts.

References (1)

Core 1

Scores

CVSS v4 7.4
EPSS 0.0043
EPSS Percentile 34.6%
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
Rupeeseed Technology Ventures/RupeeWeb <66.9
Published Feb 14, 2025
Tracked Since Feb 18, 2026