CVE-2026-6355
Received
Received - Intake
Insecure Direct Object Reference in Web App Enables Unauthorized Data Access
Publication date: 2026-04-22
Last updated on: 2026-04-22
Assigner: CERT/CC
Description
Description
A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configuration.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| augmentt | augmentt_web_application | to 2025-10-01 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |