A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version 1.10.0 is sufficient to resolve this issue. The patch is named 6fc91c49eebdb8bfdfeed71cb50a5d97eac70f24. It is advisable to upgrade the affected component.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version 1.10.0 is sufficient to resolve this issue. The patch is named 6fc91c49eebdb8bfdfeed71cb50a5d97eac70f24. It is advisable to upgrade the affected component. | |
| Title | Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication | |
| First Time appeared |
Open-web-analytics
Open-web-analytics open-web-analytics |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:open-web-analytics:open-web-analytics:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open-web-analytics
Open-web-analytics open-web-analytics |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-09-08T20:00:11.314Z
Updated: 2026-09-08T20:00:11.314Z
Reserved: 2026-09-08T13:32:00.536Z
Link: CVE-2026-86810
No data.
Status : Deferred
Published: 2026-09-08T20:18:54.453
Modified: 2026-09-09T15:33:47.627
Link: CVE-2026-86810
No data.