An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authorization Bypass in Mautic 7 API v2 Endpoints |
Fri, 29 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2026-05-29T10:30:23.561Z
Reserved: 2026-05-28T07:56:12.387Z
Link: CVE-2026-9808
No data.
Status : Received
Published: 2026-05-29T12:16:26.800
Modified: 2026-05-29T12:16:26.800
Link: CVE-2026-9808
No data.
OpenCVE Enrichment
Updated: 2026-05-29T12:30:43Z