CVE-2026-4548

A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-22 14:16

Updated : 2026-03-23 14:31


NVD link : CVE-2026-4548

Mitre link : CVE-2026-4548

CVE.ORG link : CVE-2026-4548


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization