PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39584 Webful Creations CVE debrief

A Subscriber Broken Access Control vulnerability exists in RepairBuddy versions <= 4.1132. This vulnerability has been assigned a CVSS score of 6.5, indicating a Medium severity level. The vulnerability allows an attacker to bypass access controls, potentially leading to unauthorized access to sensitive information.

Vendor
Webful Creations
Product
RepairBuddy
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of RepairBuddy versions <= 4.1132 should be aware of this vulnerability and take necessary steps to mitigate it.

Technical summary

The vulnerability is caused by a lack of proper access controls in the RepairBuddy plugin. This allows a subscriber to bypass access controls and potentially access sensitive information. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.

Defensive priority

MEDIUM

Recommended defensive actions

  • Update to a version of RepairBuddy greater than 4.1132.
  • Review and restrict access controls to sensitive information.

Evidence notes

Evidence for this vulnerability comes from Patchstack, as referenced in the CVE record.

Official resources

CVE-2026-39584 was published on 2026-06-15T21:16:47.800Z and modified on 2026-06-15T21:24:32.790Z.