8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e.g. using a debugger) and log in as any other user or administrator - then it is possible to do every possible change to the repository.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 17.1 and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 17.1 and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
AI Analysis
Authorization bypass vulnerability in Sparx Enterprise Architect allowing attackers to modify client behavior and log in as other users or administrators
Basic Information
ID
CVE-2026-42098
Source
CERT-PL
Published
May 19, 2026 at 12:59
Affected Product
Vendor
Sparx Systems
Product
Enterprise Architect
Affected Versions
Sparx Systems Enterprise Architect 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Sparx Systems
Product
Enterprise Architect
Version
17.1 and below