{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-10285","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-05-31T16:30:13.123Z","datePublished":"2026-06-01T19:15:26.718Z","dateUpdated":"2026-06-02T12:22:08.130Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-06-01T19:15:26.718Z"},"title":"DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-285","lang":"en","description":"Improper Authorization"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-266","lang":"en","description":"Incorrect Privilege Assignment"}]}],"affected":[{"vendor":"DevaslanPHP","product":"project-management","versions":[{"version":"2.0.0-beta1","status":"affected"}],"cpes":["cpe:2.3:a:devaslanphp:project-management:*:*:*:*:*:*:*:*"],"modules":["Ticket Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":5.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.4,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5.5,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-05-31T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-05-31T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-05-31T18:35:20.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Mitchell_45 (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/367578","name":"VDB-367578 | DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper authorization","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/367578/cti","name":"VDB-367578 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-10285","name":"CVE-2026-10285 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/825475","name":"Submit #825475 | devaslanphp project-management < 2.0.0-beta1 Improper Authorization","tags":["third-party-advisory"]},{"url":"https://github.com/devaslanphp/project-management/issues/141","tags":["broken-link","issue-tracking"]},{"url":"https://github.com/devaslanphp/project-management/","tags":["broken-link","product"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-02T12:21:46.930341Z","id":"CVE-2026-10285","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-02T12:22:08.130Z"}}]}}