What is CVE-2026-52466?
This vulnerability involves incorrect access control in Open Library Foundation VuFind versions 11.0.3 and 4.1. The flaw exists because the application does not stop processing a request in AbstractBase::validateAccessPermission after determining that controller-level permissions deny access, potentially allowing unauthorized actions. Users are advised to apply the necessary patches immediately.
Azərbaycanca: Bu boşluq Open Library Foundation VuFind v11.0.3 və v4.1 versiyalarında səhv giriş nəzarətinə aid edilir. Zəiflik, AbstractBase::validateAccessPermission metodunda icazələr rədd edildikdən sonra sorğunun emalının dayandırılmaması səbəbindən baş verir, bu da icazəsiz girişə yol aça bilər. İstifadəçilərə təcili olaraq yeniləmə tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Open Library Foundation VuFind are affected by CVE-2026-52466?
CVE-2026-52466 affects versions 11.0.3 and 4.1 of Open Library Foundation VuFind.
What is the technical cause of the unauthorized access in CVE-2026-52466?
The flaw occurs because the application does not stop processing a request in AbstractBase::validateAccessPermission after controller-level permissions deny access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.