CVE-2026-40252 - Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT
CVE ID :CVE-2026-40252
Published : April 10, 2026, 9:16 p.m. | 2 hours, 52 minutes ago
Description :FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulner...
Related Vulnerabilities
- CVE-2026-23780: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in HIGH
- CVE-2025-58913: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio HIGH
- CVE-2026-4162: The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and HIGH
- CVE-2026-33551: An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0. LOW
- CVE-2026-33784: A Use of Default Password vulnerability in the Juniper Networks
Support Insights (JSI)
Virtual L CRITICAL
Related Coverage
Threat Actors