Description
A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version 1.10.0 is sufficient to resolve this issue. The patch is named 6fc91c49eebdb8bfdfeed71cb50a5d97eac70f24. It is advisable to upgrade the affected component.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper authentication enabling potential unauthorized access
Action: Immediate Patch
AI Analysis

Impact

A flaw in the checkCapabilityAndAuthenticateUser function of Core/Controller.php allows an attacker to manipulate input and bypass the authentication checks. This results in improper authentication, which can grant unauthorized users access to application functionality or data. The weakness is identified as CWE‑287, an authentication bypass issue.

Affected Systems

The vulnerability exists in Open‑Web‑Analytics versions up to and including 1.9.1. The vendor is Open‑Web‑Analytics, and the affected component is the Controller module. Version 1.10.0 patches the issue, as indicated by the referenced commit.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is uncertain. The remote attacker initiates the attack by manipulating requests to the vulnerable function, potentially gaining unauthorized access to the system.

Generated by OpenCVE AI on September 9, 2026 at 09:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading Open‑Web‑Analytics to version 1.10.0 or later.
  • If an upgrade cannot be performed immediately, restrict unauthenticated access to privileged endpoints (e.g., /admin) via an authentication gateway or firewall rules.
  • Conduct an audit of the authentication configuration and enforce multi‑factor authentication for privileged accounts to reduce the impact of any remaining vulnerabilities.

Generated by OpenCVE AI on September 9, 2026 at 09:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version 1.10.0 is sufficient to resolve this issue. The patch is named 6fc91c49eebdb8bfdfeed71cb50a5d97eac70f24. It is advisable to upgrade the affected component.
Title Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication
First Time appeared Open-web-analytics
Open-web-analytics open-web-analytics
Weaknesses CWE-287
CPEs cpe:2.3:a:open-web-analytics:open-web-analytics:*:*:*:*:*:*:*:*
Vendors & Products Open-web-analytics
Open-web-analytics open-web-analytics
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Open-web-analytics Open-web-analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-10T17:45:26.757Z

Reserved: 2026-09-08T13:32:00.536Z

Link: CVE-2026-86810

cve-icon Vulnrichment

Updated: 2026-09-10T17:45:19.574Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:18:54.453

Modified: 2026-09-10T18:18:10.460

Link: CVE-2026-86810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:00:09Z

Weaknesses