CVE-2026-77767 – Reconmap
CVSS 7.5
IMPORTANT
Zero Day – Immediate Deployment
“An anonymous attacker can enumerate sensitive penetration-testing projects and client details without logging in.”
Reconmap contains a High-severity authorization flaw in the report preview function. CVE-2026-77767 allows unauthenticated remote users to query sequential project IDs and retrieve project names, descriptions, and linked client organisation details without membership or role checks. The CVSS score is 7.5, which is High severity.
The issue exposes sensitive engagement and customer information and also reveals valid project identifiers through response behavior. Public proof-of-concept material is available.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-862
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.