A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. | |
| Title | LinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-30T21:15:12.518Z
Reserved: 2026-04-30T14:38:49.163Z
Link: CVE-2026-7502
No data.
Status : Received
Published: 2026-04-30T22:16:26.710
Modified: 2026-04-30T22:16:26.710
Link: CVE-2026-7502
No data.
OpenCVE Enrichment
No data.