CVE-2026-90598 | jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2 UserController.java UserController.updateUser userid authorization (Issue 172)

SecurityVulns

A vulnerability was found in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. It has been rated as critical. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass.

This vulnerability is cataloged as CVE-2026-90598. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More