Impact
The flaw resides in the CPAResource endpoint of Seakee CPA‑Manager‑Plus, where the HTTP handler fails to enforce proper authorization checks. A remote attacker can trigger the vulnerable endpoint and gain unauthorized access to resources that should require privileged credentials. This leads to exposure of sensitive data and the possibility of modifying or deleting configuration settings, thereby compromising the confidentiality and integrity of the entire application. Affected systems include installations of Seakee CPA‑Manager‑Plus up to and including version 1.11.10. The patch is included in release 1.11.11, identified by commit 842eec791377ddcbea5cd639bc065eaa4801d656. Risk assessment shows a CVSS score of 6.9, representing a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only remote access to the HTTP service; the attacker needs no local privileges, and the path to compromise is straightforward once the service is reachable, making the threat tangible for exposed deployments.
Affected Systems
Seakee CPA‑Manager‑Plus, version 1.11.10 and earlier.
Risk and Exploitability
The vulnerability scores a CVSS of 6.9, indicating moderate impact. The EPSS score is less than 1%, implying a low but non‑zero likelihood of exploitation. The vulnerability is not catalogued in the CISA KEV list. The attack vector is remote over HTTP; the attacker can trigger the CPAResource endpoint without authentication or local privilege escalation. Once the service is reachable, exploitation conditions are minimal, making the potential impact readily realizable for exposed installations.
OpenCVE Enrichment