CVE-2026-22230: OPEXUS eCASE Audit incorrect access control
Published Jan 8, 2026
·Updated
OPEXUS eCASE Audit allows an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an administrator. Fixed in eCASE Platform 11.14.1.0.
Affected Software
2 affected components
OPEXUS eCASE Platform<11.14.1.0
Opexustech Ecase Audit<11.14.1.0
Event History
Jan 8, 2026
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 29, 58046
Event
via FIRST·12:45 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-22230?
CVE-2026-22230 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2026-22230?
To fix CVE-2026-22230, upgrade to OPEXUS eCASE Platform version 11.14.1.0 or higher.
3
What are the risks associated with CVE-2026-22230?
The risks associated with CVE-2026-22230 include unauthorized access to restricted functions or modifications of client-side JavaScript.
4
Which versions of OPEXUS eCASE Platform are affected by CVE-2026-22230?
OPEXUS eCASE Platform versions prior to 11.14.1.0 are affected by CVE-2026-22230.
5
Who can exploit CVE-2026-22230?
An authenticated attacker can exploit CVE-2026-22230 to gain unauthorized access to blocked functions.