Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Jul 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cygnux
Cygnux syspass |
|
| CPEs | cpe:2.3:a:cygnux:syspass:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cygnux
Cygnux syspass |
Mon, 27 Jul 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nuxsmin
Nuxsmin syspass |
|
| Vendors & Products |
Nuxsmin
Nuxsmin syspass |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the public link creation flow. Attackers can invoke the saveCreateFromAccountAction endpoint to cause AccountService::getDataForLink to load arbitrary target accounts without AccountFilterUser restrictions, decrypt credentials using the session master key, and serialize cleartext passwords into Vault storage on the PublicLink database row, enabling subsequent unauthenticated retrieval if the generated link hash is recovered. | |
| Title | sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-28T01:06:16.444Z
Reserved: 2026-07-22T20:26:09.982Z
Link: CVE-2026-65710
Updated: 2026-07-24T17:07:57.294Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T12:50:15Z