Skip to content

H3-2026-0072

Mass Assignment

Category VULNERABILITY
Base Score 5.0

Description

The application bound a client-supplied request field directly to a server-controlled attribute of a stored object. A mutation that set a privileged or server-owned field was accepted and the injected value persisted, confirmed by reading the object back.

Impact

An attacker can set object attributes the application never intended clients to control — escalating their own privileges, altering balances, or flipping verification/state flags on their own object.

References