Improper access control in ONE - CVE-2026-64630
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to retrieve report data outside the scope of a shared report link.
The vulnerability exists due to improper access control in the shared report link functionality when handling requests for report data. A remote user can manipulate a request to retrieve report data outside the scope of a shared report link.