Description
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality.

This issue affects MicroRealEstate: through 1.0.0-alpha3.
Published: 2026-07-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MicroRealEstate’s PDF generation feature does not enforce object‑level security checks, allowing an attacker to supply an object identifier that is returned in the objects that should remain hidden being exposed, thereby violating data confidentiality. The weakness is a classic case of CWE‑639, broken object‑level access control.

Affected Systems

The vulnerability affects all MicroRealEstate releases up to and including 1.0.0‑alpha3. Any deployment of those or work‑around is applied.

Risk and Exploitability

The CVSS score of 7.1 suggests high severity, while the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is the network‑accessible PDF generation endpoint; an attacker can send a crafted HTTP request containing an object identifier and retrieve a PDF that contains unauthorized confidential data.

Generated by OpenCVE AI on July 26, 2026 at 19:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a patched release that restores proper object‑level access controls.
  • Confirm that your deployments are not running MicroRealEstate 1.0.0‑alpha3 or earlier, and update to the latest available release if the vendor has issued a fix.
  • Configure application logging to monitor PDF generation requests and alert on abnormal access patterns, enabling detection of potential unauthorized data exposure.

Generated by OpenCVE AI on July 26, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control in PDF Generation

Tue, 21 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control in PDF Generation

Fri, 17 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control in PDF Generator Exposes Confidential Data

Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control in PDF Generator Exposes Confidential Data

Mon, 13 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control in PDF Generation

Sun, 12 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control in PDF Generation

Sat, 11 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Controls in MicroRealEstate PDF Generator

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microrealestate
Microrealestate microrealestate
Vendors & Products Microrealestate
Microrealestate microrealestate

Fri, 10 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Controls in MicroRealEstate PDF Generator

Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Broken Object-Level Access Controls in PDF Generator

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Broken Object-Level Access Controls in PDF Generator

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Microrealestate Microrealestate
cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2026-07-07T13:31:57.313Z

Reserved: 2026-06-26T00:40:34.057Z

Link: CVE-2026-57868

cve-icon Vulnrichment

Updated: 2026-07-07T13:31:54.085Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key