CVE-2026-5228
Deferred
Deferred - Pending Action
Improper Access Control in WriteUp Mobile App
Publication date: 2026-06-04
Last updated on: 2026-06-04
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects WriteUp Mobile App: from 1.3.0 through 04062026.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| kurt_software | writeup_mobile_app | From 1.3.0 (inc) to 04062026 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |