Description
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.
Published: 2026-06-04
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows attackers to use features of Kurt Software Studio WriteUp Mobile App that should be restricted by access control lists. With no proper authorization checks, a malicious user can exploit the software to reach operations they should not be able to perform, potentially exposing sensitive information or altering data. The high CVSS score of 8.8 indicates that the flaw is both serious and widely exploitable once the weakness is known.

Affected Systems

Kurt Software Studio WriteUp Mobile App versions 1.3.0 through 04062026 are affected. The flaw exists in the mobile application shipped in this range.

Risk and Exploitability

This issue is rated high severity with a CVSS score of 8.8. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is internal or local, whereby a user who has access to the application can interact with it to invoke disallowed operations. Exploitation requires only the ability to run the app; no additional domain or network privileges are indicated. Because the description does not mention remote exploitation, it is reasonable to infer that the attack is confined to the app environment. The absence of an EPSS score and KEV listing suggests that while the vulnerability is serious, there is no current evidence of widespread exploitation.

Generated by OpenCVE AI on June 4, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of WriteUp Mobile App that includes remediation for the ACL deficiency.
  • Enforce proper authorization checks by reviewing the application's access control logic and ensuring all sensitive operations are guarded by ACLs.
  • Audit user accounts and application permissions to verify that only authorized users have access to the protected features and revocation of any excess privileges.

Generated by OpenCVE AI on June 4, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.
Title Improper Access Control in Kurt Software Studio's WriteUp Mobile App
Weaknesses CWE-284
CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-06-04T17:28:38.331Z

Reserved: 2026-03-31T13:21:46.402Z

Link: CVE-2026-5228

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-04T16:16:39.640

Modified: 2026-06-04T16:23:33.747

Link: CVE-2026-5228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T16:30:06Z

Weaknesses