Description
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization.

This issue affects MicroRealEstate: through 1.0.0-alpha3.
Published: 2026-07-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MicroRealEstate’s Template API does not enforce object‑level access controls, allowing an attacker who can specify a template identifier to retrieve templates belonging to other organizations without proper authorization.

Affected Systems

All installations of MicroRealEstate up to and including the 1.0.0-alpha3 release are affected. The issue is confined to the core product's Template API component used for managing and storing organization‑specific document templates.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the use of authenticated or unauthenticated HTTP requests to the Template API endpoints, where the attacker supplies a template identifier that belongs to a different organization. By exploiting this flaw, an attacker can retrieve templates that they are not permitted to view. This is strictly a data expose without direct impact on system integrity or availability.

Generated by OpenCVE AI on July 25, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MicroRealEstate to a release that addresses the object‑level access control flaw.
  • Restrict the Template API so that only authenticated users can query templates and validate that the template identifier belongs to the requesting organization.
  • Configure firewalls or API gateways to block or rate‑limit unauthenticated or cross‑organization access to the Template API endpoint.
  • Enable logging for template access requests to detect unauthorized usage.

Generated by OpenCVE AI on July 25, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control Exposes Organization Templates in MicroRealEstate

Tue, 21 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control Exposes Organization Templates in MicroRealEstate

Thu, 16 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Template API Access Control Bypass Allows Unauthorized Template Retrieval

Tue, 14 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Template API Access Control Bypass Allows Unauthorized Template Retrieval

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Document Templates via Broken Object‑Level Access Control

Sat, 11 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Document Templates via Broken Object‑Level Access Control

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microrealestate
Microrealestate microrealestate
Vendors & Products Microrealestate
Microrealestate microrealestate

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Object‑Level Access Control Bypass Allows Unauthorized Retrieval of Document Templates

Wed, 08 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Object‑Level Access Control Bypass Allows Unauthorized Retrieval of Document Templates

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Templates via Broken Object‑Level Access Control

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Templates via Broken Object‑Level Access Control

Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Microrealestate Microrealestate
cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2026-07-07T13:33:17.528Z

Reserved: 2026-06-26T00:40:34.057Z

Link: CVE-2026-57870

cve-icon Vulnrichment

Updated: 2026-07-07T13:33:14.439Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T21:00:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key