Impact
An incorrect authorization flaw in acmailer permits a user to create a sub‑account that inherits administrative privileges. This vulnerability undermines access controls and allows an attacker to gain full control of the system without legitimate credentials. The weakness is identified as a failure to enforce proper authorization checks, as classified by CWE‑863.
Affected Systems
The affected products are acmailer CGI and acmailer DB, both produced by Extra Innovation Inc. No specific version information is available in the current data set.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, reflecting potential for total compromise. EPSS data is unavailable, so the current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is via the web interface or API of acmailer, suggesting remote exploitation from any network location that can reach the application. An attacker would create a privileged sub‑account and subsequently carry out unauthorized administrative actions.
OpenCVE Enrichment