CRITICAL 9.3 NVD

CVE-2026-69703

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to b

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.

References

Published: 2026-08-04 · Source: NVD · Feed updated: 2026-08-04
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-04 via NVD.

Risk Timeline

CVE Disclosed2026-08-04 · -1 days ago

Remediation Resources

vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.