Sceawere

Vulnerability Detail

CVE-2026-78258UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Booking and Rental Manager Broken Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Magepeople inc.
Product
Booking and Rental Manager
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-24T12:16:54.747Z",
  "pubdate": "2026-08-24T12:16:54.747Z",
  "executiveSummary": "The vulnerability identified is an unauthenticated broken access control flaw affecting the Booking and Rental Manager plugin in versions 2.7.5 and below. This security defect allows remote, unauthenticated attackers to bypass authorization checks and interact with restricted functionalities or data within the affected system. The presence of broken access control introduces severe risk implications, potentially leading to unauthorized data exposure, manipulation of booking records, or execution of privileged operations without valid user sessions. The impact spans confidentiality and integrity breaches of the managed booking data. Exploitation requires network connectivity to the target application hosting the vulnerable plugin, but does not necessitate prior authentication, user interaction, or valid privilege levels. Threat actors can leverage this flaw by sending crafted HTTP requests directly to exposed endpoints that lack proper session validation and access restriction enforcement. Remediation requires applying official vendor patches or updating to a secure version where access control enforcement is correctly implemented across all administrative and management pathways.",
  "technicalDetails": "The root cause of this vulnerability stems from improper authorization checks within the Booking and Rental Manager plugin for versions 2.7.5 and prior. Specifically, the application fails to validate whether incoming HTTP requests originate from authenticated users possessing the appropriate administrative or managerial privileges before processing sensitive operations or returning restricted data structures.\nThe vulnerable component consists of the access control mechanism guarding internal routing or function calls associated with the plugin's booking and rental management logic. Due to the absence of robust capability checks, session validation, or nonce verification on critical endpoints, the underlying code assumes that requests are authorized by default.\nThe attack flow proceeds as follows: An unauthenticated threat actor identifies the target web application running a vulnerable version of the Booking and Rental Manager plugin. The attacker crafts an HTTP request targeting specific backend functions, administrative endpoints, or data retrieval interfaces exposed by the plugin. Because the affected code lacks proper access control validation, the server processes the request without enforcing authentication or privilege requirements. The application then executes the requested function or returns the requested restricted data directly to the unauthenticated client.\nThe attack vector is network-based, exposing the application over HTTP or HTTPS depending on the target deployment configuration. No specific payload behavior beyond standard HTTP request manipulation is required to trigger the underlying logic flaw. Post-exploitation impact includes unauthorized access to booking schedules, customer data, and rental parameters, as well as potential state modification depending on the specific endpoints exposed to the unauthenticated context."
}
CVE-2026-78258: Booking and Rental Manager Broken Access Control (MEDIUM Severity, CVSS: 5.3) - Sceawere