PatchSiren

metasfresh CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH metasfresh CVE published 2026-09-16

CVE-2026-92752

CVE-2026-92752 is a high-severity vulnerability in metasfresh's DocumentAttachmentsRestController and CommentsRestController endpoints. The issue allows attackers to read, replace, and delete attachments and comments on records they cannot access by enumerating sequential document identifiers. This vulnerability requires verification of affected versions and remediation from official sources.