CVE-2026-5652

· NIST NVD ↗

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.

CRITICAL
CVSS severity
9
CVSS base score
2026-04-21
Published

CWE codes

CWE-639

Affected products

craftycontrol:crafty_controller

Sources