PatchSiren cyber security CVE debrief
CVE-2026-65435 Thrive Themes Coupon CVE debrief
CVE-2026-65435 is a MEDIUM severity vulnerability with a CVSS score of 6.5. It is an Unauthenticated Broken Access Control issue in Thrive Leads Version <= 10.9.2. The vulnerability allows attackers to bypass access controls, potentially leading to unauthorized actions. Users of Thrive Leads Version <= 10.9.2 should apply patches or mitigations to prevent exploitation. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L.
- Vendor
- Thrive Themes Coupon
- Product
- Thrive Leads Version
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Users of Thrive Leads Version <= 10.9.2, security teams, and platform operators should apply patches or mitigations to prevent exploitation of Unauthenticated Broken Access Control. Affected deployments should be identified and prioritized for remediation.
Technical summary
CVE-2026-65435 is an Unauthenticated Broken Access Control vulnerability in Thrive Leads Version <= 10.9.2. The vulnerability has a CVSS score of 6.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L. The issue allows attackers to bypass access controls, potentially leading to unauthorized actions. Defenders should focus on applying patches or mitigations to prevent exploitation.
Defensive priority
Apply patches or mitigations to prevent exploitation of Unauthenticated Broken Access Control in Thrive Leads. Identify and prioritize affected deployments for remediation.
Recommended defensive actions
- Apply patches or updates to Thrive Leads to version > 10.9.2
- Implement compensating controls to restrict access to sensitive areas
- Monitor for suspicious activity related to Thrive Leads
- Review and update asset inventory to identify exposed systems
- Verify security controls and detection capabilities for Thrive Leads
Evidence notes
The CVE record was published on 2026-07-27T15:17:08.760Z and last modified on 2026-07-27T17:46:02.447Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments and review official advisories.
Official resources
-
CVE-2026-65435 CVE record
CVE.org
-
CVE-2026-65435 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T15:17:08.760Z and has not been modified since then. The NVD entry is currently Deferred.