Sceawere

Vulnerability Detail

CVE-2026-66699UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dokan Broken Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
Dokan, Inc.
Product
Dokan
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Custom role Broken Access Control in Dokan <= 5.0.10 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-06T15:17:22.853Z",
  "pubdate": "2026-08-06T15:17:22.853Z",
  "executiveSummary": "A broken access control vulnerability has been identified in Dokan versions 5.0.10 and prior, specifically related to custom role management.\nThis vulnerability allows unauthorized threat actors to bypass security boundaries and interact with restricted functionalities associated with custom roles.\nThe affected product is the Dokan multi-vendor marketplace solution, which impacts the overall authorization integrity of the application.\nThe risk implications include unauthorized privilege escalation, unauthorized data access, and potential manipulation of platform resources depending on the defined custom roles.\nAn attacker possessing low privileges or unauthenticated access, depending on the specific endpoint exposure, can leverage this flaw to execute actions reserved for higher-privileged administrative or management roles.\nExploitation requirements typically involve interacting with improperly secured endpoints or manipulating role assignment requests within the application context.",
  "technicalDetails": "The root cause of this vulnerability lies in inadequate input validation and missing function-level access control checks within the custom role handling mechanisms of Dokan.\nThe vulnerable component handles role-based permissions and access rights assignment across the multi-vendor marketplace framework.\nAffected versions include all instances of Dokan up to and including version 5.0.10.\nThe vulnerability is exposed over the network via HTTP/HTTPS requests processed by the application backend.\nAuthentication and privilege requirements are bypassed due to the flawed authorization logic, allowing users with standard or restricted roles to invoke sensitive methods intended exclusively for administrative entities.\nThe attack flow proceeds as follows: First, the adversary identifies the targeted endpoints responsible for managing or utilizing custom roles within the Dokan architecture. Second, the attacker crafts an arbitrary request targeting these privileged functions without possessing the requisite administrative context. Third, due to the absence of robust server-side validation verifying whether the current session context maps to an authorized custom role with sufficient privileges, the backend application processes the request. Finally, the system executes the requested operation, granting the attacker unauthorized access to restricted features or data.\nPost-exploitation impact includes unauthorized modification of user permissions, potential data exfiltration of sensitive vendor and customer information, and administrative takeover of the marketplace ecosystem."
}
CVE-2026-66699: Dokan Broken Access Control Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere