


Perceptive Security
SOC/SIEM Consultancy

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-sc…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 13:02:21
Source:
nvd.nist.gov
Web Technologies, Identity & Access
An authorization bypass vulnerability in Mautic 7 API v2 endpoints allows low-privilege authenticated users to bypass ownership controls. The vulnerability affects roles with owner-scope restrictions like viewown and editown permissions. Attackers can access or modify resources belonging to other users by exploiting improperly enforced ownership-logic controls in the API Platform implementation.
Technical details
Mitigation steps:
Affected products:
Mautic
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-9808
https://github.com/mautic/mautic/security/advisories/GHSA-2jrw-c95w-h43g
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
