PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65708 nuxsmin CVE debrief

CVE-2026-65708 is an insecure direct object reference vulnerability in sysPass through version 3.2.11. Authenticated attackers can access account file attachments without ACL permissions by exploiting missing authorization checks in AccountFileController. This vulnerability allows attackers to supply arbitrary numeric file IDs through various actions to enumerate and manipulate attachments, bypassing account-level access controls entirely. The CVSS score for this vulnerability is 8.6, indicating a high severity.

Vendor
nuxsmin
Product
sysPass
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-24
Original CVE updated
2026-07-27
Advisory published
2026-07-24
Advisory updated
2026-07-27

Who should care

sysPass users and administrators should be aware of this vulnerability and take steps to remediate it. Authenticated attackers can exploit this vulnerability to access account file attachments without proper permissions, potentially leading to unauthorized access to sensitive information.

Technical summary

The vulnerability exists in the AccountFileController of sysPass through version 3.2.11. Attackers can supply arbitrary numeric file IDs through various actions to enumerate and manipulate attachments, bypassing account-level access controls. The CVSS score for this vulnerability is 8.6, indicating a high severity. Affected systems should be identified, and patches or updates should be applied to remediate the vulnerability.

Defensive priority

High priority should be given to remediating this vulnerability, as it allows authenticated attackers to access sensitive information without proper permissions. Defenders should focus on applying patches or updates, implementing compensating controls, and monitoring affected systems for potential exploitation attempts.

Recommended defensive actions

  • Inventory and verify sysPass installations to identify potential exposure.
  • Apply vendor patches or updates to remediate the vulnerability.
  • Implement compensating controls, such as monitoring and access restrictions, if patches cannot be applied immediately.
  • Conduct regular security audits to detect and address similar vulnerabilities.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-07-24T17:17:34.433Z and last modified on 2026-07-27T20:36:13.407Z. The NVD entry is currently Deferred. The vulnerability affects sysPass through version 3.2.11 and allows authenticated attackers to access account file attachments without proper permissions. Evidence of exploitation is limited, and defenders should verify affected systems and apply patches or mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T17:17:34.433Z and has not been modified since then. The NVD entry is currently Deferred.