CVE-2026-10285

Source
https://cve.org/CVERecord?id=CVE-2026-10285
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10285.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10285
Published
2026-06-01T19:15:26.718Z
Modified
2026-08-07T11:31:08.329907434Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization
Details

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10285.json",
    "cwe_ids": [
        "CWE-266",
        "CWE-285"
    ]
}
References

Affected packages

Git / github.com/devaslanphp/project-management

Affected ranges

Type
GIT
Repo
https://github.com/devaslanphp/project-management
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.0.0-beta1"
        },
        {
            "last_affected": "2.0.0-beta1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.0.0-beta1
v2.*
v2.0.0-beta1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10285.json"