CVE-2026-57869: Microrealestate

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.

Affected products

Published 2026-07-07. Last modified 2026-07-07.