Skip to content
Threat Feed

Vendor

SysPass

3 briefs RSS
high advisory

Command Injection in sysPass via FileBackupService

An authenticated command injection vulnerability (CVE-2026-63725) in sysPass allows administrative users to execute arbitrary OS commands through unsanitized backup path configurations.

sysPass
3t 1c
high advisory

CVE-2026-65709 - sysPass JSON-RPC API Missing Object-Level Authorization

sysPass versions up to 3.2.11 are affected by a missing object-level authorization vulnerability in the JSON-RPC API. Attackers holding an API token can exploit this flaw by invoking AccountController methods (e.g., viewAction, editAction, deleteAction, editPassAction) without proper AccountFilterUser checks, allowing them to enumerate account metadata, overwrite passwords, and delete user accounts across the entire vault, bypassing per-account access control defined by their token permissions.

sysPass +1 vulnerability authorization-bypass api-exploitation cve missing-authorization credential-disclosure web-application
5t 3c
high advisory

sysPass Insecure Direct Object Reference Vulnerability (CVE-2026-65708)

An insecure direct object reference vulnerability (CVE-2026-65708) in sysPass versions up to 3.2.11 allows authenticated attackers to bypass access controls, accessing, enumerating, and manipulating account file attachments by manipulating numeric file IDs in `AccountFileController` actions without proper authorization checks, leading to unauthorized data access.

sysPass <= 3.2.11 idor access-control-bypass web-application data-exfiltration
2t 1c