CVE-2026-57870: Microrealestate

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.

Affected products

Published 2026-07-07. Last modified 2026-07-07.