CVE 8.8 HIGH

Avo: Broken Access Control: Unauthorized Execution of Arbitrary Action Classes Across Resources_CVE-2026-42205

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to insecure action lookup logic, an authenticated user can execute any Action class (descendants of Avo::BaseAction) on any resource, even if the action is not registered for that specific resource. This leads to Privilege Escalation and unauthorized data manipulation across the entire application. This issue has been patched in version 3.31.2.

AI Analysis

Broken access control vulnerability allowing authenticated users to execute arbitrary Action classes on any resource

Basic Information

ID CVE-2026-42205
Source GitHub_M
Published May 8, 2026 at 21:26

Affected Product

Vendor avo-hq
Product avo
Version < 3.31.2
Affected Versions avo-hq avo < 3.31.2

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Avo HQ
Product Avo
Version < 3.31.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.