No analysis available yet.
Vendor Solution
No solution has been reported yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their privileges by sending an HTTP request with a manipulated 'identifier' field. Successful exploitation of this vulnerability could allow an authenticated user to obtain administrator privileges. It is not possible to escalate privileges through the graphical user interface. | |
| Title | Multiple vulnerabilities in MphRx's Minerva | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-04-28T13:40:55.237Z
Reserved: 2026-04-08T08:32:51.109Z
Link: CVE-2026-5781
Updated: 2026-04-28T13:40:51.037Z
Status : Received
Published: 2026-04-28T13:19:22.717
Modified: 2026-04-28T13:19:22.717
Link: CVE-2026-5781
No data.
OpenCVE Enrichment
No data.