CVE-2026-5230
Deferred Deferred - Pending Action

Improper Access Control in Pizzy Library

Vulnerability report for CVE-2026-5230, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-15

Last updated on: 2026-06-15

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-15
Last Modified
2026-06-15
Generated
2026-07-06
AI Q&A
2026-06-15
EPSS Evaluated
2026-07-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mia_technology_inc pizzy_library From 1.0.0.26250 (inc) to 1.3.9.26250 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Access Control and Missing Authorization issue in the Pizzy Library developed by MIA Technology Inc. It allows attackers to exploit incorrectly configured access control security levels, meaning that the system does not properly restrict access to certain functions or data.

Impact Analysis

The vulnerability can lead to unauthorized access to sensitive information or functionality within the Pizzy Library. According to the CVSS score of 7.1, it has a high impact on confidentiality, a low impact on integrity, and no impact on availability, which means attackers could gain access to confidential data but may have limited ability to alter data or disrupt services.

Compliance Impact

The vulnerability involves improper access control and missing authorization in the Pizzy Library, which could lead to unauthorized access to sensitive data.

Such unauthorized access issues can potentially impact compliance with standards and regulations like GDPR and HIPAA, which require strict access controls to protect personal and health information.

However, specific impacts on compliance are not detailed in the provided information.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5230. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart