CVE 9.4 CRITICAL

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7165

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

The vulnerability is present in the ‘/addJugador’ endpoint:
* The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ information without requiring prior authorization validation. This could enable an authenticated attacker to alter any user’s ID and change their information.

* The ‘punts’ and ‘numObjectiusEliminats’ fields allow arbitrary data to be added because user input is not properly validated. This makes it possible to obtain authentic prizes, awarded by city councils, by falsifying game scores.

* In the ‘tokens’ field, administrative privileges can be self-assigned without server validation or prior authentication. This vulnerability could allow an authenticated attacker to grant themselves administrator permissions and thus escalate privileges.

* Numeric fields allow the entry of extremely long values, which can cause the system to crash. Successful exploitation of this vulnerability could allow an authenticated attacker to launch a denial-of-service (DoS) attack, preventing created games from being playable.

* The ‘urlImatge’ parameter allows server-side requests to arbitrary URLs, enabling the retrieval of users’ internal IP addresses, access to internal services, reading of local files, and unauthorized interaction with third-party APIs. An authenticated attacker could gain access to sensitive data.

AI Analysis

Multiple vulnerabilities in the Assassin game allow authenticated attackers to modify user information, falsify game scores, escalate privileges, launch denial-of-service attacks, and gain access to sensitive data.

Basic Information

ID CVE-2026-7165
Source INCIBE
Published Jun 22, 2026 at 12:46

Affected Product

Vendor Gaudire
Product Assassin game
Version last version
Affected Versions Gaudire Assassin game last version

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor Gaudire
Product Assassin game
Version last version

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.