8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to insecure action lookup logic, an authenticated user can execute any Action class (descendants of Avo::BaseAction) on any resource, even if the action is not registered for that specific resource. This leads to Privilege Escalation and unauthorized data manipulation across the entire application. This issue has been patched in version 3.31.2.
AI Analysis
Broken access control vulnerability allowing authenticated users to execute arbitrary Action classes on any resource
Basic Information
ID
CVE-2026-42205
Source
GitHub_M
Published
May 8, 2026 at 21:26
Affected Product
Vendor
avo-hq
Product
avo
Version
< 3.31.2
Affected Versions
avo-hq avo < 3.31.2
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Avo HQ
Product
Avo
Version
< 3.31.2