Broken Access Control - Vulnerability

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
February 24, 2026
Last Seen
July 24, 2026

Broken Access Control is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

Broken Access Control is a vulnerability tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed February 24, 2026; most recent activity July 24, 2026.

Related Threat Clusters

  • Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products

    The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket has a serious broken access control vulnerability. This flaw allows attackers with valid user credentials to bypass multi-factor authentication…

    3 articles · Updated June 17, 2026
  • Vatican Prayer App Exposes 700K Users' Personal Information

    The Click To Pray app, endorsed by the Pope, has leaked over 700,000 users' personal information due to an Insecure Direct Object Reference (IDOR) vulnerability. Discovered by ethical hacker BobDaHacker in January 2026,…

    9 articles · Updated July 24, 2026
  • Critical Vulnerabilities in SolarWinds Serv-U Software Patched

    SolarWinds has issued security updates for four critical remote code execution vulnerabilities in its Serv-U software, which could allow attackers to gain root access to unpatched servers. The affected software is used…

    19 articles · Updated February 24, 2026

Recent Intelligence Reports

  • Vatican's Official Prayer App Leaks 700K+ Global Users' PII — Darkreading · July 24, 2026
  • Broken Access Control in syracom AG Secure Login (2FA) for Atlassian Jira / Confluence / Bitbucket — Sec-Consult · June 17, 2026
  • SolarWinds Serv-U has some critical security flaws, so users should update now or face attack — Techradar · February 25, 2026
  • Patch these 4 critical, make-me — Theregister · February 24, 2026

Frequently asked questions

What is Broken Access Control?

Broken Access Control is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

Is Broken Access Control still active?

The most recent intelligence report mentioning Broken Access Control on ThreatCluster is dated July 24, 2026. Activity was first observed February 24, 2026, giving a tracked span from then to July 24, 2026.

What is Broken Access Control associated with?

Across ThreatCluster reporting, Broken Access Control most frequently co-occurs with Data Breach, Phishing, La Machi Communication, Pope's Worldwide Prayer Network, CVE-2025-40538, among 12 tracked related entities.

What are the latest developments involving Broken Access Control?

The most significant recent cluster is “Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products” (3 articles · Updated June 17, 2026). Broken Access Control appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Broken Access Control?

Broken Access Control appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown