ImportantSecurity & Privacy
CVE-2026-92752: metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in ... (CVSS 8.7)
metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, and delete attachments and comments on records their role cannot access.
Vulners1 min read
