CVE-2026-45342 | Kovah LinkAce up to 2.5.5 Authorization Policy Layer userCanUpdateModel Link authorization (GHSA-cj8f-h888-m57m)
A vulnerability labeled as critical has been found in Kovah LinkAce up to 2.5.5. Affected by this issue is the function AuthorizesUserApiActions::userCanUpdateModel of the component Authorization Policy Layer. The manipulation of the argument Link results in authorization bypass.
This vulnerability is cataloged as CVE-2026-45342. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.