CVE 6.3 MEDIUM

ItzCrazyKns Vane API route.ts missing authentication_CVE-2026-9371

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the component API. The manipulation leads to missing authentication. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit has been disclosed publicly and may be used. It appears that basic authentication is planned.

Basic Information

ID CVE-2026-9371
Source VulDB
Published May 24, 2026 at 09:45

Affected Product

Vendor ItzCrazyKns
Product Vane
Version 1.12.0
Affected Versions ItzCrazyKns Vane 1.12.0
ItzCrazyKns Vane 1.12.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.