CVE-2026-41464
ProjeQtor < 12.4.4 Missing Authorization via objectDetail.php
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data belonging to other users including password hashes and API keys. Attackers can bypass access controls by directly accessing the endpoint without ownership or role-based validation to extract administrator credentials and perform privilege escalation.
| CWE | CWE-862 |
| Vendor | projeqtor |
| Product | projeqtor |
| Published | Apr 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for projeqtor projeqtor
Be the first to know when new medium vulnerabilities affecting projeqtor projeqtor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
ProjeQtor / ProjeQtor
7.0 โค 12.4.3
References
Credits
Yassine Damiri Noรฉ Susset