PatchSiren

igms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM igms CVE published 2026-04-08

CVE-2026-39652

A Missing Authorization vulnerability in iGMS Direct Booking plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iGMS Direct Booking: from n/a through <= 1.3. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of iGMS Direct Booking plugin up to version 1.3 should apply patches or mitigations to prevent potential unauthorize [truncated]