CVE-2026-57870: Microrealestate
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
Affected products
- Microrealestate Microrealestate: up to and including 1.0.0-alpha3
Published 2026-07-07. Last modified 2026-07-07.