CVE-2026-7165Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ information without requiring prior authorization validation. This could enable an authenticated attacker to alter any user’s ID and change their information. * The ‘punts’ and ‘numObjectiusEliminats’ fields allow arbitrary data to be added because user input is not properly validated. This makes it possible to obtain authentic prizes, awarded by city councils, by falsifying game scores. * In the ‘tokens’ field, administrative privileges can be self-assigned without server validation or prior authentication. This vulnerability could allow an authenticated attacker to grant themselves administrator permissions and thus escalate privileges. * Numeric fields allow the entry of extremely long values, which can cause the system to crash. Successful exploitation of this vulnerability could allow an authenticated attacker to launch a denial-of-service (DoS) attack, preventing created games from being playable. * The ‘urlImatge’ parameter allows server-side requests to arbitrary URLs, enabling the retrieval of users’ internal IP addresses, access to internal services, reading of local files, and unauthorized interaction with third-party APIs. An authenticated attacker could gain access to sensitive data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-22: 3Technical Details · 2026-06-22: 306-22
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7165 The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ informatio… https://www.cve.org/CVERecord?id=CVE-2026-7165 ----- Traducción: CVE-2026-7165 La … http://infoflow.cloud`

    Post summary

    The post notes that CVE-2026-7165 involves the /addJugador endpoint where specific parameters allow unauthorized modification of user data, but it offers no evidence of a PoC, exploit, patch, or active exploitation.

    0000033
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7165 The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ informatio… https://www.cve.org/CVERecord?id=CVE-2026-7165

    Post summary

    CVE-2026-7165 exposes a flaw in the '/addJugador' endpoint where 'keyJugador' and 'keyJugadorObjectiu' parameters can be manipulated to alter other users’ data.

    00000704
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7165 Authenticated Privilege Escalation and Multiple Input Validation Vulnerabilities in '/addJugador' Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7165

    Post summary

    The text provides a short description of CVE-2026-7165 but contains no evidence of PoC, exploit code, active exploitation, patch, or false positive claim.

    00000116
    4.1K followersView on X

Explore more