Skip to content
cyberHIGH2026-05-08 22:16 UTC

CVE-2026-42205 - Avo: Broken Access Control: Unauthorized Execution of Arbitrary Action Classes Across Resources

CVE ID :CVE-2026-42205 Published : May 8, 2026, 10:16 p.m. | 47 minutes ago Description :Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to insecur

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber