
CVE-2026-5652 An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification a… https://www.cve.org/CVERecord?id=CVE-2026-5652
Post summary
The text announces an IDOR vulnerability (CVE‑2026‑5652) in Crafty Controller’s Users API that permits an authenticated, remote attacker to modify user data.

