CVE-2026-96880 | TaleLin lin-cms-spring-boot up to 0.2.1 book Endpoint BookController.java getBook ID improper authorization
A vulnerability marked as problematic has been reported in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing a manipulation of the argument ID results in improper authorization.
This vulnerability is reported as CVE-2026-96880. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More