CRITICAL
daptin
CVE published 2026-08-10
CVE-2026-72575
The CVE-2026-72575 record describes an improper authorization vulnerability in daptin through v0.12.34. This vulnerability allows unauthenticated remote attackers to read, create, update, and delete usergroup records due to flawed permission check functions in server/permission/permission.go. The functions (CanRead, CanPeek, CanCreate, CanUpdate, CanDelete, CanRefer) return true whenever p.UserId equals t [truncated]