CVE-2026-28163: Mycred New User Approve

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8.

Affected products

  • Mycred New User Approve: up to and including 3.2.8

Published 2026-08-20. Last modified 2026-08-24.