CVE-2026-86810
Deferred Deferred - Pending Action

Improper Authentication in Open-Web-Analytics

Vulnerability report for CVE-2026-86810, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: VulDB

Description

A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version 1.10.0 is sufficient to resolve this issue. The patch is named 6fc91c49eebdb8bfdfeed71cb50a5d97eac70f24. It is advisable to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
open-web-analytics open-web-analytics to 1.9.1 (inc)
open-web-analytics open-web-analytics 1.10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authentication issue in Open-Web-Analytics versions up to 1.9.1. The flaw exists in the checkCapabilityAndAuthenticateUser function of Core/Controller.php, where unauthenticated users can bypass authentication checks if a controller does not explicitly set a required capability. This allows remote attackers to execute actions that should require authentication.

Detection Guidance

To detect this vulnerability, check if your Open Web Analytics version is below 1.10.0. Run commands like 'cd /path/to/owa && git log --oneline | grep 6fc91c4' to verify the patch. Inspect Core/Controller.php for the checkCapabilityAndAuthenticateUser function to confirm proper capability checks.

Impact Analysis

An attacker could exploit this to perform unauthorized actions on the system, such as applying schema updates, accessing sensitive data, or modifying configurations without proper authentication. This could lead to data breaches, system compromise, or unauthorized changes to the analytics platform.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's access controls. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Upgrade Open Web Analytics to version 1.10.0 or later immediately. Replace the Core/Controller.php file with the patched version or apply the commit 6fc91c49eebdb8bfdfeed71cb50a5d97eac70f24. Ensure admin capability checks and nonce verification are enforced for sensitive actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86810. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart