CVE-2026-5652 is an insecure direct object reference vulnerability in the Users API component of Crafty Controller that permits authenticated attackers to modify user accounts through inadequate API permissions validation. The flaw has been assigned a CVSS score of 9.0 (Critical), indicating significant risk potential with high impact across confidentiality, integrity, and availability. The attack requires network access and high-level privileges but demands minimal complexity, enabling remote exploitation by authenticated users with administrative credentials. The vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and appears inactive on threat intelligence hot lists, suggesting limited active exploitation in the wild. However, the FAUCET Risk Score of 52.0 and relative rarity among disclosed CVEs warrants monitoring and timely remediation to prevent potential unauthorized account manipulation within affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.10.4CPE matchmatch criteria | cpe:2.3:a:craftycontrol:crafty_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.