CVE-2026-65710 is a missing authorization vulnerability in sysPass through version 3.2.11. An authenticated user with the PUBLICLINK_CREATE profile flag can exploit the absence of AccountAcl checks in the public link creation flow to trigger unauthorized decryption and persistent storage of any vault account's password. The vulnerability is caused by the lack of AccountFilterUser restrictions in the saveC [truncated]
The CVE record for CVE-2026-65709 was published on 2026-07-24T17:17:34.573Z. The vulnerability affects sysPass through version 3.2.11 and involves a missing object-level authorization in the JSON-RPC API, allowing unauthorized account modifications. Security teams and administrators responsible for sysPass installations should be aware of this vulnerability. The NVD entry is currently Deferred. An executi [truncated]
CVE-2026-65708 is an insecure direct object reference vulnerability in sysPass through version 3.2.11. Authenticated attackers can access account file attachments without ACL permissions by exploiting missing authorization checks in AccountFileController. This vulnerability allows attackers to supply arbitrary numeric file IDs through various actions to enumerate and manipulate attachments, bypassing acco [truncated]