Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.3

Directory Pro can let unauthorized users access sensitive data

CVE-2026-27396
Summary

The Directory Pro software has a security issue that means some users may be able to access areas of the system they shouldn't. This can lead to sensitive data being accessed or modified. Users of Directory Pro version 2.5.6 and earlier should update to a newer version to fix this issue.

Original title
Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a throu...
Original description
Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6.
Vulnerability type
CWE-862 Missing Authorization
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026