CRITICAL 9.3 NVD
CVE-2026-69703
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to b
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.
References
- https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6
- https://github.com/maximeAmini/Atals-Livre
- https://www.vulncheck.com/advisories/atlas-livre-unauthenticated-access-via-admin-controll
- https://gist.github.com/arjunjaincs/8cd878b6628d587a1139febd40de9ac6
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-04 via NVD.
Risk Timeline
CVE Disclosed2026-08-04 · -1 days ago
Remediation Resources
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.