← Back to overview

UnoPim versions before 2.1.3 contain a missing authorization vulnerability where integration store, update, and key-generation routes are not included in the ACL map. This allows any admin user with minimal privileges to bypass permission checks enforced by the Bouncer middleware. Attackers can exploit this flaw to create OAuth API integrations, mint client credentials, and escalate their permissions within the application. The vulnerability stems from inadequate authorization validation in the middleware layer. A fix was introduced in UnoPim version 2.1.3 via a commit to the Bouncer middleware. The issue is tracked as CVE-2026-85395 and has been documented by VulnCheck and the NVD.

Affected products

  • UnoPim

Related CVE's

  • CVE-2026-85395

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies