What is CVE-2026-72575?
This is an improper authorization vulnerability in daptin up to version 0.12.34. Unauthenticated remote attackers can read, create, update, and delete usergroup records due to always-true permission check functions. Upgrading daptin to the latest version is recommended.
Azərbaycanca: Bu boşluq daptin platformasının 0.12.34 versiyasına qədər olan sistemlərində avtorizasiya zəifliyidir. İdentifikasiya olunmamış uzaqdan hücum edən şəxs istifadəçi qrupu qeydlərini oxuya, yarada, yeniləyə və silə bilər. daptin sistemini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of daptin are affected by CVE-2026-72575?
This vulnerability affects daptin up to version 0.12.34.
What can an attacker do by exploiting this authorization vulnerability?
Unauthenticated remote attackers can read, create, update, and delete usergroup records.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.