CVE-2026-85395
UnoPim before 2.1.3 Missing Authorization on Integration Management Routes
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.
| CWE | CWE-862 |
| Vendor | unopim |
| Product | unopim |
| Published | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unopim unopim
Be the first to know when new high vulnerabilities affecting unopim unopim are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
Affected Versions
unopim / unopim
0 < 2.1.3
References
github.com: https://github.com/unopim/unopim/commit/acbf2e160ced78446d6e4267e89f264bf04612c4 github.com: https://github.com/unopim/unopim github.com: https://github.com/unopim/unopim/releases/tag/v2.1.3 github.com: https://github.com/unopim/unopim/blob/v2.1.2/packages/Webkul/User/src/Http/Middleware/Bouncer.php github.com: https://github.com/geo-chen/oss/blob/main/unopim.md vulncheck.com: https://www.vulncheck.com/advisories/unopim-before-2.1.3-missing-authorization-on-integration-management-routes
Credits
George Chen