What is CVE-2026-59535?
This is an unauthenticated Broken Access Control vulnerability in Thrive Product Manager versions <= 10.9.2. It may allow unauthorized users to access certain restricted functionalities. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu boşluq Thrive Product Manager plagininin 10.9.2 və daha əvvəlki versiyalarında autentifikasiya olunmamış "Broken Access Control" zəifliyidir. İstismar nəticəsində icazəsiz şəxslər müəyyən funksiyalara giriş əldə edə bilər. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the Thrive Product Manager plugin are affected by CVE-2026-59535?
This Broken Access Control vulnerability affects Thrive Product Manager versions 10.9.2 and earlier.
How can I protect my system from CVE-2026-59535?
The most effective protection against this vulnerability is to update the plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.