CRITICAL
Open Library Foundation
CVE published 2026-08-06
CVE-2026-52466
The Open Library Foundation VuFind vulnerability allows unauthorized access to functions despite access control checks. This critical severity vulnerability, with a CVSS score of 9.8, affects Open Library Foundation VuFind versions v11.0.3 and v4.1. The vulnerability is caused by the application's failure to stop processing an incoming request in VuFindControllerAbstractBase::validateAccessPermission afte [truncated]