CVE-2026-7502
MEDIUMLinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization
Title source: cnaDescription
A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
Scores
CVSS v3
5.4
EPSS
0.0004
EPSS Percentile
12.9%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-285
CWE-639
Status
published
Products (7)
LinkStackOrg/LinkStack
4.8.0
LinkStackOrg/LinkStack
4.8.1
LinkStackOrg/LinkStack
4.8.2
LinkStackOrg/LinkStack
4.8.3
LinkStackOrg/LinkStack
4.8.4
LinkStackOrg/LinkStack
4.8.5
LinkStackOrg/LinkStack
4.8.6
Published
Apr 30, 2026
Tracked Since
May 01, 2026