Vulnerability Description
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6
- https://github.com/maximeAmini/Atals-Livre
- https://www.vulncheck.com/advisories/atlas-livre-unauthenticated-access-via-admi
- https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6
FAQ
What is CVE-2026-69703?
CVE-2026-69703 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guard...
How severe is CVE-2026-69703?
CVE-2026-69703 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-69703?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.