PatchSiren cyber security CVE debrief
CVE-2026-42666 Dimitri Grassi CVE debrief
CVE-2026-42666 is a HIGH severity vulnerability with a CVSS score of 7.5. It is an Unauthenticated Broken Access Control issue affecting the Salon booking system plugin versions up to 10.30.25.
- Vendor
- Dimitri Grassi
- Product
- Salon booking system
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-15
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-15
- Advisory updated
- 2026-06-15
Who should care
Users of Salon booking system plugin versions up to 10.30.25 should apply patches or mitigations to prevent exploitation.
Technical summary
The vulnerability, categorized under CWE-862, allows unauthenticated access due to broken access control in the Salon booking system plugin. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating a high impact on confidentiality.
Defensive priority
HIGH
Recommended defensive actions
- Apply patches or updates to Salon booking system plugin versions up to 10.30.25.
- Refer to resourceLinkAnnotations for mitigation or vendor references.
Evidence notes
Evidence suggests that the vulnerability was reported by [email protected] and is listed in the NVD.
Official resources
-
CVE-2026-42666 CVE record
CVE.org
-
CVE-2026-42666 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
CVE-2026-42666 was published on 2026-06-15T21:16:56.393Z and modified on 2026-06-15T21:24:32.790Z.