CVE-2026-50881

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.

Published 2026-06-15. Last modified 2026-06-17.