PatchSiren cyber security CVE debrief
CVE-2026-65708 nuxsmin CVE debrief
CVE-2026-65708 is an insecure direct object reference vulnerability in sysPass through version 3.2.11. Authenticated attackers can access account file attachments without ACL permissions by exploiting missing authorization checks in AccountFileController. This vulnerability allows attackers to supply arbitrary numeric file IDs through various actions to enumerate and manipulate attachments, bypassing account-level access controls entirely. The CVSS score for this vulnerability is 8.6, indicating a high severity.
- Vendor
- nuxsmin
- Product
- sysPass
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-24
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-24
- Advisory updated
- 2026-07-27
Who should care
sysPass users and administrators should be aware of this vulnerability and take steps to remediate it. Authenticated attackers can exploit this vulnerability to access account file attachments without proper permissions, potentially leading to unauthorized access to sensitive information.
Technical summary
The vulnerability exists in the AccountFileController of sysPass through version 3.2.11. Attackers can supply arbitrary numeric file IDs through various actions to enumerate and manipulate attachments, bypassing account-level access controls. The CVSS score for this vulnerability is 8.6, indicating a high severity. Affected systems should be identified, and patches or updates should be applied to remediate the vulnerability.
Defensive priority
High priority should be given to remediating this vulnerability, as it allows authenticated attackers to access sensitive information without proper permissions. Defenders should focus on applying patches or updates, implementing compensating controls, and monitoring affected systems for potential exploitation attempts.
Recommended defensive actions
- Inventory and verify sysPass installations to identify potential exposure.
- Apply vendor patches or updates to remediate the vulnerability.
- Implement compensating controls, such as monitoring and access restrictions, if patches cannot be applied immediately.
- Conduct regular security audits to detect and address similar vulnerabilities.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record was published on 2026-07-24T17:17:34.433Z and last modified on 2026-07-27T20:36:13.407Z. The NVD entry is currently Deferred. The vulnerability affects sysPass through version 3.2.11 and allows authenticated attackers to access account file attachments without proper permissions. Evidence of exploitation is limited, and defenders should verify affected systems and apply patches or mitigations.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T17:17:34.433Z and has not been modified since then. The NVD entry is currently Deferred.