CVE-2026-3209: Improper Parameter Precedence Auth Bypass
Detects an authorization or parameter validation bypass where a batch array input incorrectly takes precedence over a single ID input via short-circuiting. If an attacker provides a valid array in the request body alongside an unauthorized single targeted ID in the URL parameter, the application might validate the array but act on the targeted ID. Prioritize
greprules fetch cve-2026-3209-improper-parameter-precedence-auth-bypass --engine opengrepDescription
Detects an authorization or parameter validation bypass where a batch array input incorrectly takes precedence over a single ID input via short-circuiting. If an attacker provides a valid array in the request body alongside an unauthorized single targeted ID in the URL parameter, the application might validate the array but act on the targeted ID. Prioritize
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.