CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69703

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-04
Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record deletion by requesting controller endpoints with GET parameters like supp, because the PHP header() redirect is never followed by an exit or die call, allowing all subsequent code including database operations to execute regardless of session state.

⚡ Watch CVE-2026-69703

Get an email if CVE-2026-69703 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69703

CVE.org record

Embed the live status

CVE-2026-69703 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69703 status](https://www.csirts.com/badge/CVE-2026-69703)](https://www.csirts.com/cve/CVE-2026-69703)