CVE-2026-96882 Details
Description
A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
An unauthorized access vulnerability exists in TaleLin lin-cms-spring-boot versions through 0.2.1. The issue is located in the book search function of the BookController component. This vulnerability allows remote attackers to access book information without authorization by exploiting the unprotected search endpoint. The lack of permission verification enables unauthorized queries that retrieve detailed data about all books.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hhhh333/CVE/blob/main/Lin-CMS-%E6%9C%AA%E6%8E%88%E6%9D%833.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-96882 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/906083 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/409080 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/409080/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TaleLin lin-cms-spring-boot | <= 0.2.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion