CVE-2026-49249 | Malach-IT Boruta Server up to 0.9.x UserSettingsController BorutaIdentityWeb.UserSettingsController.update User resource consumption
A vulnerability described as problematic has been identified in Malach-IT Boruta Server up to 0.9.x. This issue affects the function BorutaIdentityWeb.UserSettingsController.update of the component UserSettingsController. Such manipulation of the argument User leads to resource consumption.
This vulnerability is referenced as CVE-2026-49249. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More