An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mautic
Mautic mautic |
|
| Vendors & Products |
Mautic
Mautic mautic |
Fri, 29 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass in Mautic 7 API v2 Endpoints |
Fri, 29 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mautic
Published: 2026-05-29T10:30:23.561Z
Updated: 2026-05-29T14:42:37.155Z
Reserved: 2026-05-28T07:56:12.387Z
Link: CVE-2026-9808
Updated: 2026-05-29T14:42:33.933Z
Status : Deferred
Published: 2026-05-29T12:16:26.800
Modified: 2026-05-29T15:39:34.620
Link: CVE-2026-9808
No data.