Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Wakyma has fixed the vulnerability in the continuous integration deployed in production since February 19, 2026.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 16 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing the victim's email address, validating the new email address, and requesting a new password. This could allow them to take complete control of other users' legitimate accounts | |
| Title | Identity based authorization bypass vulnerability (IDOR) in the Wakyma application web | |
| First Time appeared |
Wakyma
Wakyma wakyma Application Web |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:wakyma:wakyma_application_web:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Wakyma
Wakyma wakyma Application Web |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-16T15:27:44.272Z
Reserved: 2026-02-23T13:43:53.578Z
Link: CVE-2026-3020
Updated: 2026-03-16T15:27:34.393Z
Status : Awaiting Analysis
Published: 2026-03-16T14:19:45.150
Modified: 2026-03-16T14:53:07.390
Link: CVE-2026-3020
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:02:53Z