CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-9765

highCVSS 7.1covered by 1 sourcefirst seen 2026-07-24
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and gain unauthorized access to resources that are not available with their permissions. Broken access control can allow attackers to: Access resources only accessible to certain users, thus allowing unauthorized access to data Perform operations on behalf of other users, leading to account takeovers in the worst cases Attempt privilege escalation Attempt to take over an account

⚡ Watch CVE-2026-9765

Get an email if CVE-2026-9765 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-9765

CVE.org record

Embed the live status

CVE-2026-9765 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-9765 status](https://www.csirts.com/badge/CVE-2026-9765)](https://www.csirts.com/cve/CVE-2026-9765)