Sceawere

Vulnerability Detail

CVE-2026-66701UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Broken Access Control in Profile Builder

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
Cozmoslabs
Product
Profile Builder
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-06T15:17:22.987Z",
  "pubdate": "2026-08-06T15:17:22.987Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability exists in Profile Builder versions 3.16.5 and below. This security flaw permits unauthenticated remote attackers to bypass authorization controls and interact with privileged functionality or access restricted data within the affected system. The vulnerability presents a significant risk to confidentiality and integrity, potentially allowing unauthorized modifications or data exposure without requiring valid user credentials. Exploitation requires network access to the target application where Profile Builder is deployed. The root cause stems from insufficient access restriction checks on sensitive endpoints, failing to properly validate whether the requesting entity possesses the necessary privileges before processing requests. Security implications include unauthorized administrative actions, data leakage, and potential system compromise depending on the extent of accessible functionality exposed through the affected pathways. Remediation requires applying vendor-supplied updates or patches that properly enforce access control mechanisms and authentication validation checks.",
  "technicalDetails": "The vulnerability is classified as a Broken Access Control flaw affecting the Profile Builder product, specifically impacting all versions up to and including 3.16.5. The root cause of the issue lies in the absence of robust authorization checks and session validation within the application's request-handling logic. Specifically, the vulnerable component fails to adequately verify the authentication status and permission levels of incoming requests before executing sensitive backend functions.\nFrom an attack flow perspective, an unauthenticated malicious actor can interact directly with the exposed functionality over the network without supplying any session tokens, cookies, or valid credentials. Because the application lacks proper access control enforcement, the request is processed as if it originated from a legitimate, authorized user. The attack vector is completely remote and requires no prior privileges or interaction from a privileged user.\nDuring exploitation, the payload behavior leverages the lack of input and permission validation to trigger restricted operations or retrieve unauthorized data structures. Depending on the specific execution context within Profile Builder, this lack of access control can lead to unauthorized data retrieval, configuration tampering, or state changes within the application.\nPost-exploitation impact includes the potential exposure of sensitive user profiles, unauthorized execution of restricted application features, and potential escalation of privileges within the broader CMS ecosystem where Profile Builder is integrated. The absence of strict authorization boundaries invalidates the trust model of the affected software, allowing arbitrary unauthenticated entities to bypass intended security perimeters."
}
CVE-2026-66701: Unauthenticated Broken Access Control in Profile Builder (MEDIUM Severity, CVSS: 5.3) - Sceawere