Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ente
Ente museum Server |
|
| Vendors & Products |
Ente
Ente museum Server |
|
| Metrics |
cvssV3_1
|
Wed, 29 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's account via a crafted `approve-recovery` API request. | |
| Title | Ente Museum Server Authorization Bypass Vulnerability | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-07-30T13:40:06.238Z
Reserved: 2026-07-23T12:58:51.242Z
Link: CVE-2026-16751
Updated: 2026-07-30T13:39:50.512Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T14:02:30Z
No weakness.