Stats Digest Feeds
← Back to all CVEs

CVE-2026-8077

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published May 08, 2026
Vendor unknown

Description

Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls, leaving security entirely to the frontend. By modifying the binary string in the β€˜Permissions’ field of the JSON response, an attacker could escalate privileges and gain full administrative access. This vulnerability allows all restrictions to be bypassed and completely compromises system management.

References