CVE-2026-65709
HIGHsysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
Title source: cnaDescription
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without AccountFilterUser checks to modify or delete accounts beyond the scope of their assigned token permissions.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/Caycon/cve-advisories/blob/main/2026/sysPass/CVE-2026-65709.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/syspass-missing-object-level-authorization-via-json-rpc-api
Scores
CVSS v3
8.3
EPSS
0.0022
EPSS Percentile
13.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (1)
nuxsmin/sysPass
< 3.2.11
Published
Jul 24, 2026
Tracked Since
Jul 24, 2026