CVE-2026-65435 is a MEDIUM severity vulnerability with a CVSS score of 6.5. It is an Unauthenticated Broken Access Control issue in Thrive Leads Version <= 10.9.2. The vulnerability allows attackers to bypass access controls, potentially leading to unauthorized actions. Users of Thrive Leads Version <= 10.9.2 should apply patches or mitigations to prevent exploitation. The CVSS vector is CVSS:3.1/AV:N/AC: [truncated]
CVE-2026-59535 is a HIGH-severity vulnerability in Thrive Product Manager plugin versions <= 10.9.2. It allows unauthenticated broken access control, with a CVSS score of 7.3. The vulnerability class is broken access control. Likely operational impact includes unauthorized access. Source confidence is high based on CVE and NVD data. Review context includes official CVE and NVD records.