H3-2026-0072¶
Mass Assignment
| Category | VULNERABILITY |
| Base Score | 5.0 |
Description¶
The application bound a client-supplied request field directly to a server-controlled attribute of a stored object. A mutation that set a privileged or server-owned field was accepted and the injected value persisted, confirmed by reading the object back.
Impact¶
An attacker can set object attributes the application never intended clients to control — escalating their own privileges, altering balances, or flipping verification/state flags on their own object.