What is CVE-2026-65504?
CVE-2026-65504 is an unauthenticated Broken Access Control vulnerability in BOX NOW Delivery Croatia plugin versions 3.3.0 and below. This flaw allows remote attackers to gain unauthorized access to restricted functionalities without providing any credentials. Updating to the latest patched version immediately is strongly recommended.
Azərbaycanca: CVE-2026-65504 BOX NOW Delivery Croatia plaqininin 3.3.0 və aşağı versiyalarında autentifikasiya olunmamış "Broken Access Control" zəifliyidir. Bu qüsur uzaqdan hücumçulara heç bir giriş etimadnaməsi olmadan məhdudlaşdırılmış funksionallıqlara icazəsiz giriş imkanı yaradır. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the BOX NOW Delivery Croatia plugin are affected by CVE-2026-65504?
This vulnerability affects plugin versions 3.3.0 and below.
Does an attacker need authentication credentials to exploit CVE-2026-65504?
No, this flaw is an unauthenticated Broken Access Control vulnerability, meaning attackers can gain unauthorized access to restricted functionalities without providing any credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.