CVE-2026-3739 Details
Description
A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerializer of the file src/backend/core/api/serializers.py of the component ThreadAccess. The manipulation results in improper authentication. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.3.0 is capable of addressing this issue. The patch is identified as d7729f4b885449f6dee3faf8b5f2a05769fb3d6e. The affected component should be upgraded.
A vulnerability allowing improper authentication has been identified in Suitenumerique Messages version 0.2.0. The issue resides in the ThreadAccessSerializer within the file src/backend/core/api/serializers.py. This vulnerability allows authenticated users to manipulate ThreadAccess records, potentially accessing or modifying threads they should not have permission to.
Users are advised to upgrade to Suitenumerique Messages version 0.3.0, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 8, 2026CISA-ADP
Assessed Mar 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/suitenumerique/messages/ | [email protected] | ProductSource CodeVendor |
| https://github.com/suitenumerique/messages/commit/d7729f4b885449f6dee3faf8b5f2a05769fb3d6e | [email protected] | Source CodeVendor |
| https://github.com/suitenumerique/messages/pull/557 | [email protected] | Issue TrackingVendor |
| https://github.com/suitenumerique/messages/releases/tag/v0.3.0 | [email protected] | Release NotesVendor |
| https://github.com/suitenumerique/messages/security/advisories/GHSA-7476-6crq-4cw9 | [email protected] | AdvisoryExploitTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.349717 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.349717 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.767329 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| suitenumerique messages | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 8, 2026 | New CVE Received | [email protected] |
Volerion