Vulnerability Description
ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data belonging to other users including password hashes and API keys. Attackers can bypass access controls by directly accessing the endpoint without ownership or role-based validation to extract administrator credentials and perform privilege escalation.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://damiri.fr/en/cves/CVE-2026-41464
- https://gryfman.fr/cves/CVE-2026-41464
- https://www.projeqtor.com
- https://www.vulncheck.com/advisories/projeqtor-missing-authorization-via-objectd
FAQ
What is CVE-2026-41464?
CVE-2026-41464 is a vulnerability with a CVSS score of 6.5 (MEDIUM). ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive d...
How severe is CVE-2026-41464?
CVE-2026-41464 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41464?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.