PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52699 e4jvikwp CVE debrief

CVE-2026-52699 is a HIGH severity vulnerability in VikRentCar <= 1.4.5 versions. The vulnerability is an Unauthenticated Insecure Direct Object References (IDOR) with a CVSS score of 7.5. It was published on 2026-06-15T21:17:24.503Z and last modified on 2026-06-15T21:24:32.790Z. The vulnerability allows attackers to access sensitive information without authentication.

Vendor
e4jvikwp
Product
VikRentCar
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of VikRentCar plugin version <= 1.4.5 should apply the necessary patches to prevent exploitation.

Technical summary

The vulnerability is caused by an Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar plugin version <= 1.4.5. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.

Defensive priority

HIGH

Recommended defensive actions

  • Apply the patch as soon as possible.
  • Review and update the plugin to the latest version.

Evidence notes

The vulnerability was reported by [email protected] and is referenced in the NVD database.

Official resources

CVE-2026-52699 was published on 2026-06-15T21:17:24.503Z and last modified on 2026-06-15T21:24:32.790Z.