CVE-2026-22230

HIGH

OPEXUS eCASE Audit < 11.14.1.0 - Authenticated Incorrect Authorization via Client-Side JavaScript Manipulation

Title source: llm
STIX 2.1

Description

OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an administrator. Fixed in eCASE Platform 11.14.1.0.

References (3)

Core 3

Scores

CVSS v3 7.6
EPSS 0.0029
EPSS Percentile 20.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
opexustech/ecase_audit < 11.14.1.0
Published Jan 08, 2026
Tracked Since Feb 18, 2026