CVE-2026-22660

HIGH

FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint

Title source: cna
STIX 2.1

Description

FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. The bulk AJAX endpoint in the management views compares received JSON integer group IDs against string literals, causing the protection check to always pass, which allows deletion of all six built-in groups and destroys the forum's permission model, potentially rendering the site unusable.

Scores

CVSS v3 7.2
EPSS 0.0033
EPSS Percentile 25.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-697
Status published
Products (2)
flaskbb/flaskbb < 2.2.0
flaskbb/flaskbb https://github.com/flaskbb/flaskbb/commit/a5da9a52
Published Jul 10, 2026
Tracked Since Jul 10, 2026