Description
metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, and delete attachments and comments on records their role cannot access.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Unchecked Permissions
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in metasfresh arises from the DocumentAttachmentsRestController and CommentsRestController endpoints, which verify only that a caller is logged in but fail to enforce record‑level permissions. Attackers can therefore enumerate sequential document identifiers and read, replace, or delete attachments and comments on records that their role should not be able to access, exposing confidential information and allowing unauthorized modification. This flaw is an access control bypass identified as CWE‑639.

Affected Systems

The impacted product is the metasfresh ERP platform, specifically the backend controllers that manage attachments and comments. While the CNA data does not specify affected versions, any installation of metasfresh that includes these controllers is potentially vulnerable. Administrators should confirm the product version in use and consult the vendor’s release notes for a fix.

Risk and Exploitability

With a CVSS score of 8.7 this flaw is categorized as high severity, and although the EPSS score is less than 1% indicating low current exploitation probability, the condition can be triggered by any authenticated user lacking proper record‑level rights. The attack vector is likely through authenticated API calls to the vulnerable endpoints; the issue is not yet flagged in the CISA KEV catalog but should be patched promptly given its high impact.

Generated by OpenCVE AI on September 18, 2026 at 06:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest metasfresh update that addresses the missing permission checks in the attachment and comment controllers
  • If a patch is unavailable, restrict these API endpoints so that only users with explicit record‑level permissions can invoke them, and disable automatic enumeration of attachment identifiers
  • In the meantime, isolate the metasfresh service from the public network, limit access to trusted internal networks, and monitor for abnormal enumeration patterns

Generated by OpenCVE AI on September 18, 2026 at 06:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Metasfresh
Metasfresh metasfresh
Vendors & Products Metasfresh
Metasfresh metasfresh

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, and delete attachments and comments on records their role cannot access.
Title metasfresh Unauthorized Access via Document Attachments and Comments Endpoints
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Metasfresh Metasfresh
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:47:51.313Z

Reserved: 2026-09-16T18:57:08.498Z

Link: CVE-2026-92752

cve-icon Vulnrichment

Updated: 2026-09-21T15:47:21.069Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:24.023

Modified: 2026-09-23T17:17:48.190

Link: CVE-2026-92752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:11:33Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key