{"id":"CVE-2026-51956","details":"A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not enforce tenant-level ownership checks when accessing or updating company objects, allowing cross-tenant access and modification of company profile data.","modified":"2026-09-04T08:03:35.938289Z","published":"2026-09-01T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/51xxx/CVE-2026-51956.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/51xxx/CVE-2026-51956.json"},{"type":"ADVISORY","url":"https://github.com/h4vrut4/security-advisories/blob/main/CVE-2026-51956.md"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-51956"},{"type":"FIX","url":"https://github.com/Grashjs/cmms/commit/283bbc985cda497d6b592faae45ae1dbc8d53966"},{"type":"PACKAGE","url":"https://github.com/Grashjs/cmms"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grashjs/cmms","events":[{"introduced":"0"},{"fixed":"283bbc985cda497d6b592faae45ae1dbc8d53966"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-51956.json","vanir_signatures_modified":"2026-09-04T08:03:35Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/grashjs/cmms/commit/283bbc985cda497d6b592faae45ae1dbc8d53966","target":{"file":"api/src/main/java/com/grash/controller/CompanyController.java","function":"patch"},"deprecated":false,"digest":{"function_hash":"225917125490200946485022594741965734074","length":654},"id":"CVE-2026-51956-0ccc4945","signature_type":"Function"},{"digest":{"line_hashes":["138773051354327342271333155511145270411","184519246081661885830151605289044883817","20018919225318841839222162438037888351","290350690100566068732420630155959568926","68638060168767047536628588731716640125","334882324260619843912403345967743654144","55778860505213356035331947115175237737","67957091272816435852941078370113109611"],"threshold":0.9},"id":"CVE-2026-51956-411d7e03","signature_type":"Line","signature_version":"v1","source":"https://github.com/grashjs/cmms/commit/283bbc985cda497d6b592faae45ae1dbc8d53966","target":{"file":"api/src/main/java/com/grash/controller/CompanyController.java"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"16228305706303812212062183815837422093","length":355},"id":"CVE-2026-51956-d2e0d39e","signature_type":"Function","signature_version":"v1","source":"https://github.com/grashjs/cmms/commit/283bbc985cda497d6b592faae45ae1dbc8d53966","target":{"file":"api/src/main/java/com/grash/controller/CompanyController.java","function":"getById"}},{"id":"CVE-2026-51956-e7a9583f","signature_type":"Function","signature_version":"v1","source":"https://github.com/grashjs/cmms/commit/283bbc985cda497d6b592faae45ae1dbc8d53966","target":{"file":"api/src/main/java/com/grash/controller/CompanySettingsController.java","function":"getById"},"deprecated":false,"digest":{"function_hash":"252180744559500326037356101682362607658","length":342}},{"digest":{"line_hashes":["141231162406162558344032135525904095976","282144698872869039114055742795090720475","52997992327082956646996194983245800382","181492214062162596718824220256520426665"],"threshold":0.9},"id":"CVE-2026-51956-feece471","signature_type":"Line","signature_version":"v1","source":"https://github.com/grashjs/cmms/commit/283bbc985cda497d6b592faae45ae1dbc8d53966","target":{"file":"api/src/main/java/com/grash/controller/CompanySettingsController.java"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}