CVE-2026-51956

Source
https://cve.org/CVERecord?id=CVE-2026-51956
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-51956.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-51956
Published
2026-09-01T00:00:00Z
Modified
2026-09-04T03:47:30.356662394Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/51xxx/CVE-2026-51956.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/grashjs/cmms

Affected ranges

Type
GIT
Repo
https://github.com/grashjs/cmms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v1.*
v1.1.0
v1.2.0
v1.3.0
v1.4.0
v1.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-51956.json"