CVE-2026-75415
Received Received - Intake

Incorrect Access Control in AntFlow V2.0.0

Vulnerability report for CVE-2026-75415, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: MITRE

Description

AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing attackers to forge any user identity credential information, thereby causing sensitive information leakage.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AntFlow V2.0.0 has a vulnerability called Incorrect Access Control. The issue is in JiMuMDCCommonsRequestLoggingFilter.java where the userid is taken from the request header as part of identity verification. This allows attackers to forge user identity credentials, potentially leading to unauthorized access and sensitive data exposure.

Impact Analysis

This vulnerability could allow attackers to impersonate any user, gain unauthorized access to sensitive data, or perform actions on behalf of other users. It may lead to data breaches, unauthorized modifications, or service disruptions depending on the system's use.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to personal or health data. GDPR requires strict access controls and data protection, while HIPAA mandates safeguards for protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Immediately review and update the identity verification mechanism in JiMuMDCCommonsRequestLoggingFilter.java to prevent header-based user ID forgery. Ensure proper authentication and authorization checks are implemented.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75415. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart