Sceawere
Vulnerability Detail
CVE-2026-48199UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Broken Access Control in Sermon'e
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 16h ago
- Vendor
- Beplusthemes
- Product
- Sermon'e
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T09:17:55.930Z",
"pubdate": "2026-10-06T09:17:55.930Z",
"executiveSummary": "The vulnerability identified as Unauthenticated Broken Access Control in Sermon'e versions 1.0.2 and earlier constitutes a critical security flaw in the application's authorization logic.\nThis vulnerability allows unauthenticated, remote attackers to bypass established security constraints and access restricted resources or perform unauthorized administrative actions.\nThe flaw stems from insufficient server-side validation of user identity or session status before granting access to sensitive application functionality.\nThe risk implication is significant, as an attacker with network access to the target instance can interact with protected endpoints without providing valid credentials.\nBy manipulating requests, an attacker can effectively escalate privileges or manipulate the application state, leading to full compromise of sensitive data or administrative control.\nExploitation requires no prior authentication or specialized user interaction, making it highly accessible for automated scanning and exploitation tools targeting public-facing instances of Sermon'e.",
"technicalDetails": "The vulnerability exists within the access control mechanisms of Sermon'e <= 1.0.2, where authorization checks are either entirely absent or improperly implemented on sensitive controller endpoints or API routes.\nThe root cause is a failure to verify the authentication token or session state at the entry point of the vulnerable request handlers. The application design relies on client-side state or insecure routing logic that fails to enforce the principle of least privilege.\nIn a standard attack flow, an attacker identifies reachable endpoints that typically require administrative or authenticated sessions. By directly crafting HTTP requests—such as GET, POST, or PUT—to these target paths, the attacker circumvents the application's front-end access control layer.\nSince the backend fails to validate the request origin or session validity, the server executes the requested logic as if the user possessed appropriate permissions. This can lead to unauthorized information disclosure, the modification of application settings, or potential remote execution if the exposed functions interact with underlying system calls or database configurations.\nThe vulnerability is pervasive across the application due to a centralized design flaw where authentication middleware is either bypassed or not applied to internal modules.\nPost-exploitation, an attacker can leverage this access to perform data exfiltration, modify system configurations, or create backdoor administrative accounts to ensure persistent access. Because the application logic does not correlate the request with a valid, authenticated user session, the activity often evades standard audit logging systems that require user context."
}