Sceawere

Vulnerability Detail

CVE-2026-105070UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Privilege Escalation in Salon

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
16h ago
Vendor
Dimitri Grassi
Product
Salon booking system
Attack Type
CWE-266 Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T09:17:40.743Z",
  "pubdate": "2026-10-06T09:17:40.743Z",
  "executiveSummary": "The Salon booking system, in versions 10.31.7 and earlier, contains a critical vulnerability allowing for unauthenticated privilege escalation.\nThis vulnerability is classified as an improper authorization flaw, which permits remote, unauthenticated attackers to bypass security controls and attain elevated administrative privileges within the target application.\nThe impact of this flaw is severe, potentially leading to a total compromise of the application, including the ability to manipulate booking data, access sensitive customer information, and gain full control over the administrative backend.\nExploitation does not require prior authentication or specialized user interactions, making it highly accessible to remote threat actors. The vulnerability poses a significant risk to the confidentiality, integrity, and availability of the affected system and its underlying data.\nOrganizations utilizing affected versions of the Salon booking system should treat this as a high-priority security concern.",
  "technicalDetails": "The vulnerability originates from a failure in the application's access control mechanisms during the processing of specific requests within the Salon booking system versions 10.31.7 and lower.\nRoot cause analysis indicates that the affected component fails to validate the session state or authorization tokens before executing administrative-level operations. Because the application logic incorrectly assumes that certain request types are only reachable by authenticated users, it lacks necessary server-side checks for the caller's privilege level.\nThe exploitation flow begins with an unauthenticated attacker crafting a malicious HTTP request directed at the vulnerable endpoint responsible for managing user privileges or system configurations. Since the server-side logic does not perform adequate authentication or authorization verification for these specific requests, it processes the request as if it were sent by an authenticated administrator.\nAn attacker can leverage this flaw to send crafted requests that manipulate the user database, elevate the privileges of a standard user account to that of a super-administrator, or directly execute administrative functions. By bypassing the intended authentication boundary, the attacker effectively circumvents the security model designed to isolate administrative operations from unauthenticated access.\nThe lack of integrity verification on these requests allows an attacker to interact directly with backend functions that should be restricted. Post-exploitation, an attacker can gain persistent unauthorized access, alter site-wide settings, access sensitive database records including customer contact information and transaction logs, and potentially inject malicious code into the booking workflow. Given that this interaction occurs over the network, it is exploitable from any remote host capable of communicating with the application server, making it a critical threat to internet-facing deployments."
}
CVE-2026-105070: Unauthenticated Privilege Escalation in Salon (HIGH Severity, CVSS: 8.8) | Sceawere