CVE-2026-28230 | steve-community steve up to 3.11.0 SOAP Endpoint getTransaction access control (GHSA-6x38-4w7h-cwr8)
A vulnerability, which was classified as critical, was found in steve-community steve up to 3.11.0. This affects the function getTransaction of the component SOAP Endpoint. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-28230. It is possible to launch the attack remotely. No exploit is available.
It is best practice to apply a patch to resolve this issue.