Sceawere
Vulnerability Detail
CVE-2026-39798UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Settings Modification in TrueBooker
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 16h ago
- Vendor
- ThemetechMount
- Product
- TrueBooker
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T09:17:52.990Z",
"pubdate": "2026-10-06T09:17:52.990Z",
"executiveSummary": "The TrueBooker application, in versions 1.2.9 and earlier, contains a critical security vulnerability involving improper authorization controls. This vulnerability allows an unauthenticated, remote attacker to modify application settings without requiring valid credentials or administrative privileges. The flaw resides within the handling of requests sent to the configuration management interfaces. By manipulating specific HTTP requests, an attacker can alter system behavior, adjust security parameters, or potentially redirect application traffic. The impact of this vulnerability is significant, as it permits unauthorized state changes to the target system. Exploitation does not require prior knowledge of the target environment or user interaction, posing a substantial risk to the confidentiality, integrity, and availability of the affected instance. The vulnerability highlights a failure in the application's authentication enforcement layer, which neglects to verify the session status or privilege levels of entities attempting to commit configuration updates.",
"technicalDetails": "The vulnerability in TrueBooker version 1.2.9 and earlier is categorized as an improper access control issue, specifically an Unauthenticated Settings Change. The root cause lies in the application's request processing logic, which fails to implement mandatory authentication checks for administrative configuration endpoints. In these versions, the application processes POST or PUT requests directed toward settings-related functions without verifying if the request originates from a valid, authorized session.\nThe attack flow commences with an attacker identifying the endpoint responsible for updating system configurations. Because the application lacks server-side authorization enforcement, an attacker can craft a malicious HTTP request—potentially containing sensitive parameters or configuration overrides—and transmit it directly to the vulnerable function. The application component responsible for parsing these settings fails to validate the identity of the requester, inadvertently processing and applying the unauthorized modifications to the persistent storage or memory state of the application.\nSpecifically, the flaw allows for the modification of critical configuration variables that control application flow, security posture, and data handling. An attacker can leverage this access to disable existing security mechanisms, modify internal configuration paths, or inject arbitrary values that the system subsequently executes or acts upon. Since the vulnerability is reachable over the network and does not require authentication, it is classified as a remote, unauthenticated exploit vector. No specialized prerequisites, such as specific user roles or elevated account access, are required to trigger the vulnerable code path.\nThe post-exploitation impact includes the potential for full application control or system compromise. By altering settings that define authentication protocols, logging configurations, or data storage paths, an attacker can gain deeper access, maintain persistence, or facilitate secondary attacks, such as cross-site scripting (XSS) or arbitrary data exfiltration, by manipulating the application's internal environment to a non-secure state. The lack of proper input validation in conjunction with the absence of authorization checks renders the settings management functionality inherently insecure in all affected versions."
}