Description
OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an administrator. Fixed in eCASE Platform 11.14.1.0.
Problem types
CWE-863 Incorrect Authorization
Product status
11.4.0 (custom) before 11.14.1.0
11.14.1.0
Credits
Aaron M. Ramirez, Son Nguyen, Wesley Cuffee, United States Department of Justice
References
docs.opexustech.com/...4.X/eCASE_Release_Notes_11.14.1.0.pdf (url)
www.cve.org/CVERecord?id=CVE-2026-22230 (url)
raw.githubusercontent.com/...IT/white/2025/va-26-008-01.json (url)