๐Ÿ” CVE Alert

CVE-2026-92765

MEDIUM 6.5

ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.

CWE CWE-639
Vendor archerysec
Product archerysec
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for archerysec archerysec

Be the first to know when new medium vulnerabilities affecting archerysec archerysec are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

archerysec / archerysec
0 โ‰ค 2.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/archerysec/archerysec/issues/676 github.com: https://github.com/archerysec/archerysec github.com: https://github.com/archerysec/archerysec/blob/v2.0.6/webscanners/views.py#L297-L313 vulncheck.com: https://www.vulncheck.com/advisories/archerysec-through-2.0.6-information-disclosure-via-webscanvulnlist

Credits

George Chen