CVE-2026-85638
Received Received - Intake

Authorization Bypass in trape via vId Parameter

Vulnerability report for CVE-2026-85638, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulDB

Description

A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jofpin trape 2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in jofpin trape 2.0, specifically in the core/user.py file. It allows remote attackers to manipulate the vId or id argument to gain unauthorized access. The exploit is publicly available, increasing the risk of attacks.

Detection Guidance

This vulnerability involves an authorization bypass in jofpin trape 2.0 due to manipulation of the vId/id argument in core/user.py. To detect it, inspect network traffic for requests targeting core/user.py with modified vId/id parameters. Check application logs for unusual access patterns or unauthorized privilege escalations. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow unauthorized individuals to access sensitive data or perform actions they shouldn't. If you use jofpin trape 2.0, attackers might exploit this to bypass authentication and gain control over the system or steal information.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating GDPR and HIPAA requirements for data protection and access controls. Non-compliance may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately restrict access to the core/user.py file in jofpin trape 2.0. Review and update authorization mechanisms to prevent bypass via the vId/id parameter. Monitor network traffic for unauthorized access attempts targeting this file.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85638. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart