CVE-2026-7144
Deferred
Deferred - Pending Action
Authorization Bypass in 1000 Projects MCA via temp_user Parameter
Publication date: 2026-04-27
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| 1000_projects | portfolio_management_system | mca_1.0 |
| 1000projects | portfolio_management_system | mca |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-285 | The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. |
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |