CVE-2026-86804

    Dashboard / Vulnerabilities / CVE-2026-86804

    CVE-2026-86804

    Published: 8 Sept 2026Last Modified: 13 Sept 2026

    Summary: seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization

    Details: A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. Upgrading to version 1.11.11 is able to resolve this issue. The identifier of the patch is 842eec791377ddcbea5cd639bc065eaa4801d656. It is suggested to upgrade the affected component.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 8800dee8ec632c159cf1c3d6a707796af17ea414

    Affected versions

    1.11.0
    1.11.1
    1.11.10
    1.11.2
    1.11.3
    1.11.4
    1.11.5
    1.11.6
    1.11.7
    1.11.8
    1.11.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-86804 | CVE-DB