CVE-2026-108746 - Vearch 3.5.2 through 3.5.9 Incorrect Authorization via Role.HasPermissionForResources
CVE ID :CVE-2026-108746 Published : Oct. 11, 2026, 1:17 p.m. | 13 minutes ago Description :Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role....