CVE-2026-51956 - Grashjs Atlas CMMS Broken Object Level Authorization
Brief
CVE ID : CVE-2026-51956
Published : Sept. 1, 2026, 5:17 p. m.
- 1 hour, 59 minutes ago
Description : A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.
- 0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint.
The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
