Sceawere

Vulnerability Detail

CVE-2026-66464UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Broken Access Control in Internal Link Optimiser

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
Toast Plugins
Product
Internal Link Optimiser
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T14:17:07.707Z",
  "pubdate": "2026-08-13T14:17:07.707Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the Internal Link Optimiser product affecting versions 5.2.7 and below.\nThis security flaw introduces significant risk implications by allowing unauthenticated malicious actors to interact with restricted functionalities and administrative interfaces without possessing valid credentials or proper authorization checks.\nThe vulnerability directly impacts the security posture of systems running the affected software versions, potentially exposing internal application logic and sensitive routines normally protected by access control mechanisms.\nThe attacker capabilities include remote execution of privileged actions over the network without requiring any prior authentication tokens, user interaction, or specific role assignments.\nExploitation requirements are minimal, as the lack of authentication boundaries permits direct HTTP requests to targeted endpoints, bypassing standard security controls enforced by the application layer.\nOrganizations deploying the vulnerable software face potential compromise of data integrity and unauthorized manipulation of internal linking structures, necessitating immediate remediation through patching or restrictive access configurations.",
  "technicalDetails": "The root cause of this vulnerability lies in the absence of proper authentication and authorization checks within the request handling lifecycle of the Internal Link Optimiser application for versions <= 5.2.7.\nThe vulnerable component fails to validate whether incoming HTTP requests originate from authenticated users with appropriate administrative privileges before executing sensitive backend functions.\nBecause the affected endpoints lack session validation or role-based access control (RBAC) enforcement, network-exposed vectors allow remote unauthenticated adversaries to directly invoke restricted methods.\nThe attack flow proceeds as follows: First, the attacker identifies the exposed administrative or functional endpoints associated with the Internal Link Optimiser plugin or module. Second, the adversary crafts malicious HTTP requests targeting these unprotected functions directly, omitting any authentication headers or tokens. Third, the application processes the incoming payload without validating the caller's identity or authorization level. Finally, the server executes the requested internal logic, granting the unauthenticated actor unauthorized access to restricted features, data manipulation capabilities, or administrative operations.\nThe affected versions include Internal Link Optimiser 5.2.7 and all prior iterations containing the same flawed access control implementation.\nThe authentication and privilege requirements are entirely absent, meaning zero credentials or pre-existing privileges are necessary to successfully trigger the flaw.\nThe network exposure is direct and remote, as the vulnerable endpoints are accessible over standard web protocols (HTTP/HTTPS) wherever the plugin is active and reachable.\nPost-exploitation impact encompasses unauthorized modification of internal links, potential exposure of application internals, and further system compromise depending on the extent of functionality exposed through the unauthenticated endpoints."
}
CVE-2026-66464: Unauthenticated Broken Access Control in Internal Link Optimiser (MEDIUM Severity, CVSS: 6.5) - Sceawere