← back
CVE-2026-2669

Rongzhitong Visual Integrated Command and Dispatch Platform User delete access control

CVSS 6.9 MEDIUMEPSS 0.5%CWE-266CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
18 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impacts an unknown function of the file /dm/dispatch/user/delete of the component User Handler. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →