CVE-2026-65709 | nuxsmin sysPass up to 3.2.11 JSON-RPC API editPassAction access control
A vulnerability was found in nuxsmin sysPass up to 3.2.11 and classified as critical. Affected by this issue is the function AccountController::viewAction/AccountController::editAction/AccountController::deleteAction/AccountController::editPassAction of the component JSON-RPC API. Such manipulation leads to improper access controls.
This vulnerability is listed as CVE-2026-65709. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More