Back

HIGH

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform)

Published May 29, 2026

Description

An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users.

Affected products

Remediation

Vendor solution

There are no official workarounds. To mitigate this issue without upgrading, temporarily revoke API credentials or narrow access permissions for any users whose roles rely on owner-scope permission containment.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mautic
Published May 29, 2026
Updated May 29, 2026
Reserved May 28, 2026
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Deferred
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mautic
Published May 29, 2026
Updated May 29, 2026
Exploited since n/a
EUVD-2026-33278 GHSA-2JRW-C95W-H43G