PatchSiren

Unitech Web CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Unitech Web CVE published 2026-04-08

CVE-2026-39650

A Missing Authorization vulnerability was found in UnitechPay, affecting versions from n/a through 1.0.2. This issue allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized actions. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. It is related to CWE-862, which involves missing authorization. Users of UnitechPay [truncated]