
I found an IDOR in LollMS friend request handling: any authenticated user could accept or reject someone else's pending request by guessing sequential friendship IDs (CVE-2026-0562). Full write-up: https://aydinnyunus.github.io/2026/04/18/idor-lollms-friend-request-cve-2026-0562/ #security #websecurity #appsec #cve #bugbounty
Post summary
An IDOR vulnerability (CVE‑2026‑0562) lets authenticated users accept or reject others’ friend requests by guessing sequential ID numbers; no exploit, patch, or active attacks are mentioned.


