---
id: CVE-2026-85395
title: >-
  UnoPim before 2.1.3 fails to include integration store, update, and
  key-generation routes in its ACL map, allowing any admin user to bypass
  permission checks
summary: >-
  UnoPim before 2.1.3 fails to include integration store, update, and
  key-generation routes in its ACL map, allowing any admin user to bypass
  permission checks. Attackers with minimal admin privileges can create OAuth
  API integrations, min…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-862
published: '2026-09-03'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:45.697'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85395'
references:
  - url: 'https://github.com/geo-chen/oss/blob/main/unopim.md'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/unopim/unopim'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/unopim/unopim/blob/v2.1.2/packages/Webkul/User/src/Http/Middleware/Bouncer.php
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/unopim/unopim/commit/acbf2e160ced78446d6e4267e89f264bf04612c4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/unopim/unopim/releases/tag/v2.1.3'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/unopim-before-2.1.3-missing-authorization-on-integration-management-routes
    label: disclosure@vulncheck.com
  - url: 'https://github.com/geo-chen/oss/blob/main/unopim.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00417
epssPercentile: 0.33371
ingestedAt: '2026-09-05T20:44:37.791Z'
---

## Overview

UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
