← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 1, 2026 · 17:17via CVEFeed

CVE-2026-51956 - Grashjs Atlas CMMS Broken Object Level Authorization

Brief

CVE ID : CVE-2026-51956

Published : Sept. 1, 2026, 5:17 p. m.

  • 1 hour, 59 minutes ago

Description : A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.

  • 0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint.

The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed