PatchSiren cyber security CVE debrief
CVE-2026-39678 DOTonPAPER CVE debrief
CVE-2026-39678 is a Missing Authorization vulnerability in the DOTonPAPER Pinpoint Booking System booking-system plugin, affecting versions from n/a through <= 2.9.9.6.5. This issue allows Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability is caused by a Missing Authorization issue in the DOTonPAPER Pinpoint Booking System booking-system plugin. This allows for Exploiting Incorrectly Configured Access Control Security Levels. The CVE record was published on 2026-04-08T09:16:39.487Z and has not been modified since. The NVD entry is currently Deferred. Users of the DOTonPAPER Pinpoint Booking System booking-system plugin, especially those using versions from n/a through <= 2.9.9.6.5, should be aware of this vulnerability and take necessary actions to mitigate potential risks. Medium priority should be given to updating the DOTonPAPER Pinpoint Booking System booking-system plugin to a version that addresses this vulnerability.
- Vendor
- DOTonPAPER
- Product
- Pinpoint Booking System
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of the DOTonPAPER Pinpoint Booking System booking-system plugin, especially those using versions from n/a through <= 2.9.9.6.5, should be aware of this vulnerability and take necessary actions to mitigate potential risks.
Technical summary
The CVE-2026-39678 vulnerability is caused by a Missing Authorization issue in the DOTonPAPER Pinpoint Booking System booking-system plugin. This allows for Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. It affects versions from n/a through <= 2.9.9.6.5 of the plugin.
Defensive priority
Medium priority should be given to updating the DOTonPAPER Pinpoint Booking System booking-system plugin to a version that addresses this vulnerability.
Recommended defensive actions
- Inventory and verify the version of the DOTonPAPER Pinpoint Booking System booking-system plugin in use.
- Apply updates or patches provided by the vendor to address the vulnerability.
- Implement compensating controls, such as monitoring and access restrictions, if immediate updates are not possible.
- Review and adjust access control configurations to prevent exploitation.
Evidence notes
The CVE record was published on 2026-04-08T09:16:39.487Z and has not been modified since. The NVD entry is currently Deferred. The vulnerability details are based on information from official sources, including CVE.org and the NVD.
Official resources
-
CVE-2026-39678 CVE record
CVE.org
-
CVE-2026-39678 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:39.487Z and has not been modified since.