Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization.

This issue affects MicroRealEstate: through 1.0.0-alpha3.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Organization Templates via Broken Object‑Level Access Control in MicroRealEstate Template API

Wed, 29 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Organization Templates via Broken Object‑Level Access Control in MicroRealEstate Template API

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control Exposes Organization Templates in MicroRealEstate

Tue, 21 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Broken Object‑Level Access Control Exposes Organization Templates in MicroRealEstate

Thu, 16 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Template API Access Control Bypass Allows Unauthorized Template Retrieval

Tue, 14 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Template API Access Control Bypass Allows Unauthorized Template Retrieval

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Document Templates via Broken Object‑Level Access Control

Sat, 11 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Document Templates via Broken Object‑Level Access Control

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Microrealestate
Microrealestate microrealestate
Vendors & Products Microrealestate
Microrealestate microrealestate

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Object‑Level Access Control Bypass Allows Unauthorized Retrieval of Document Templates

Wed, 08 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Object‑Level Access Control Bypass Allows Unauthorized Retrieval of Document Templates

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Templates via Broken Object‑Level Access Control

Tue, 07 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Retrieval of Templates via Broken Object‑Level Access Control

Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2026-07-07T13:33:17.528Z

Reserved: 2026-06-26T00:40:34.057Z

Link: CVE-2026-57870

cve-icon Vulnrichment

Updated: 2026-07-07T13:33:14.439Z

cve-icon NVD

Status : Deferred

Published: 2026-07-07T06:16:22.890

Modified: 2026-07-07T14:16:33.430

Link: CVE-2026-57870

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:00:16Z

Weaknesses