


Perceptive Security
SOC/SIEM Consultancy

toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdir…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 12:07:08
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Database & Storage
CVE-2026-71252 affects the toner-management web application, where admin state-changing handlers (add.php, edit.php, delete.php) under multiple admin subdirectories performed database INSERT, UPDATE, and DELETE operations without any authentication or authorization checks. Access control was only enforced on listing views, leaving action handlers fully exposed. An unauthenticated remote attacker could directly invoke these handlers to create, modify, or delete application data. The vulnerability impacts admin sections covering toners, toner-brands, printers, and related resources. The vendor has merged a fix that requires a valid authenticated admin session before any state-changing handler is executed. This represents a broken access control issue with high impact on data integrity and availability.
Technical details
Mitigation steps:
Affected products:
toner-management
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-71252
https://github.com/raghav993/toner-management
https://github.com/raghav993/toner-management/pull/1
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
