Filtered by vendor Anitya
Subscriptions
Filtered by product Anitya
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-78360 | 1 Anitya | 1 Anitya | 2026-08-31 | 7.1 High |
| A missing authorization flaw was found in Anitya. The user deletion endpoint checks that the caller is logged in but does not check that the caller is an administrator. Any authenticated user can delete arbitrary user accounts, including administrator accounts, which can remove administrative access to the service. | ||||
Page 1 of 1.