๐Ÿ” CVE Alert

CVE-2026-85395

HIGH 7.1

UnoPim before 2.1.3 Missing Authorization on Integration Management Routes

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.

CWE CWE-862
Vendor unopim
Product unopim
Published Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for unopim unopim

Be the first to know when new high vulnerabilities affecting unopim unopim are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

unopim / unopim
0 < 2.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/unopim/unopim/commit/acbf2e160ced78446d6e4267e89f264bf04612c4 github.com: https://github.com/unopim/unopim github.com: https://github.com/unopim/unopim/releases/tag/v2.1.3 github.com: https://github.com/unopim/unopim/blob/v2.1.2/packages/Webkul/User/src/Http/Middleware/Bouncer.php github.com: https://github.com/geo-chen/oss/blob/main/unopim.md vulncheck.com: https://www.vulncheck.com/advisories/unopim-before-2.1.3-missing-authorization-on-integration-management-routes

Credits

George Chen