CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-69703 — Atlas-Livre contains an improper access control vulnerability in the admin contr...

·Source: NIST NVD

Updated:

Executive Summary

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because t

Analysis

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state. CVSS Score: 9.8. Published: 2026-08-04T19:16:54.130.

Indicators of Compromise (1)

CVE (1)
CVE-2026-69703
Source Attribution

Originally published by NIST NVD on Aug 4, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-70553 — MaxSite CMS contains a remote code execution vulnerability that allows unauthent...

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply a malicious db_dbprefix value containing a single quote to break out of a PHP string literal in application/config/databa

CVE-2026-70553
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-70552 — MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in...

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested-With header and requesting a base64-encoded path resolving to any *-ajax.php file in the codebase. Attackers can exploit this dispatcher bypass to reach privileged plugin endpoints without credentials

CVE-2026-70552
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-18810 — A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an ...

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.

CVE-2026-18810
NIST NVD