← Back to CVE search

CVE-2026-50881

Bonsai

Description

Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.

CVSS 8.1EPSS 0.248%Risk 0.83
View source
Published
2026-06-15 20:16:31
Affected versions
==6.0
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N