{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-3185",
        "tracking": {
            "current_release_date": "2026-03-20T09:32:44.460772Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-3185",
            "initial_release_date": "2026-02-25T11:34:46.378456Z",
            "revision_history": [
                {
                    "date": "2026-02-25T11:34:46.378456Z",
                    "number": "1",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-25T14:29:46.492452Z",
                    "number": "2",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (7).| CWES updated (1)."
                },
                {
                    "date": "2026-02-25T14:29:50.726899Z",
                    "number": "3",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-25T14:40:11.885472Z",
                    "number": "4",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (2).| Exploits created (1).| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-02-25T14:40:16.223169Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-25T15:50:47.291122Z",
                    "number": "6",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-02-26T14:12:55.017056Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-26T14:13:03.224313Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-26T16:26:27.490049Z",
                    "number": "9",
                    "summary": "Products connected (15).| Product Identifiers created (15).| Exploits created (1)."
                },
                {
                    "date": "2026-02-26T16:26:30.287522Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T06:51:16.183940Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (41).| References created (7)."
                },
                {
                    "date": "2026-02-28T06:51:19.804699Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-01T13:48:30.457214Z",
                    "number": "13",
                    "summary": "Products removed (14)."
                },
                {
                    "date": "2026-03-02T07:15:48.500853Z",
                    "number": "14",
                    "summary": "Products connected (14)."
                },
                {
                    "date": "2026-03-20T09:32:41.097104Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:32:43.557644Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "16"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.2-beta",
                                "product": {
                                    "name": "vers:unknown/1.3.2-beta",
                                    "product_id": "CSAFPID-5702101"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.3-beta",
                                "product": {
                                    "name": "vers:unknown/1.3.3-beta",
                                    "product_id": "CSAFPID-5702552"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.0",
                                "product": {
                                    "name": "vers:unknown/v0.6.0",
                                    "product_id": "CSAFPID-5735939"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.1",
                                "product": {
                                    "name": "vers:unknown/v0.6.1",
                                    "product_id": "CSAFPID-5735940"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.2",
                                "product": {
                                    "name": "vers:unknown/v0.6.2",
                                    "product_id": "CSAFPID-5735941"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.3",
                                "product": {
                                    "name": "vers:unknown/v0.6.3",
                                    "product_id": "CSAFPID-5735942"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.4",
                                "product": {
                                    "name": "vers:unknown/v0.6.4",
                                    "product_id": "CSAFPID-5735943"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.5",
                                "product": {
                                    "name": "vers:unknown/v0.6.5",
                                    "product_id": "CSAFPID-5735944"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.1",
                                "product": {
                                    "name": "vers:unknown/v0.7.1",
                                    "product_id": "CSAFPID-5735945"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.10",
                                "product": {
                                    "name": "vers:unknown/v0.7.10",
                                    "product_id": "CSAFPID-5735946"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.11",
                                "product": {
                                    "name": "vers:unknown/v0.7.11",
                                    "product_id": "CSAFPID-5735947"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.2",
                                "product": {
                                    "name": "vers:unknown/v0.7.2",
                                    "product_id": "CSAFPID-5735948"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.3",
                                "product": {
                                    "name": "vers:unknown/v0.7.3",
                                    "product_id": "CSAFPID-5735949"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.4",
                                "product": {
                                    "name": "vers:unknown/v0.7.4",
                                    "product_id": "CSAFPID-5735950"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.5",
                                "product": {
                                    "name": "vers:unknown/v0.7.5",
                                    "product_id": "CSAFPID-5735951"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.6",
                                "product": {
                                    "name": "vers:unknown/v0.7.6",
                                    "product_id": "CSAFPID-5735952"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.7",
                                "product": {
                                    "name": "vers:unknown/v0.7.7",
                                    "product_id": "CSAFPID-5735953"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.8",
                                "product": {
                                    "name": "vers:unknown/v0.7.8",
                                    "product_id": "CSAFPID-5735954"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.9",
                                "product": {
                                    "name": "vers:unknown/v0.7.9",
                                    "product_id": "CSAFPID-5735955"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.0",
                                "product": {
                                    "name": "vers:unknown/v0.8.0",
                                    "product_id": "CSAFPID-5735956"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.1",
                                "product": {
                                    "name": "vers:unknown/v0.8.1",
                                    "product_id": "CSAFPID-5735957"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.2",
                                "product": {
                                    "name": "vers:unknown/v0.8.2",
                                    "product_id": "CSAFPID-5735958"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.3",
                                "product": {
                                    "name": "vers:unknown/v0.8.3",
                                    "product_id": "CSAFPID-5735959"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.4",
                                "product": {
                                    "name": "vers:unknown/v0.8.4",
                                    "product_id": "CSAFPID-5735960"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.5",
                                "product": {
                                    "name": "vers:unknown/v0.8.5",
                                    "product_id": "CSAFPID-5735961"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.6",
                                "product": {
                                    "name": "vers:unknown/v0.8.6",
                                    "product_id": "CSAFPID-5735962"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.7",
                                "product": {
                                    "name": "vers:unknown/v0.8.7",
                                    "product_id": "CSAFPID-5735963"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.8",
                                "product": {
                                    "name": "vers:unknown/v0.8.8",
                                    "product_id": "CSAFPID-5735964"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.9.0",
                                "product": {
                                    "name": "vers:unknown/v0.9.0",
                                    "product_id": "CSAFPID-5735965"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-beta",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-beta",
                                    "product_id": "CSAFPID-5735966"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.1-beta",
                                "product": {
                                    "name": "vers:unknown/v1.0.1-beta",
                                    "product_id": "CSAFPID-5735967"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.2-beta",
                                "product": {
                                    "name": "vers:unknown/v1.0.2-beta",
                                    "product_id": "CSAFPID-5735968"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0-beta",
                                "product": {
                                    "name": "vers:unknown/v1.1.0-beta",
                                    "product_id": "CSAFPID-5735969"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0-beta",
                                "product": {
                                    "name": "vers:unknown/v1.2.0-beta",
                                    "product_id": "CSAFPID-5735970"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.1-beta",
                                "product": {
                                    "name": "vers:unknown/v1.2.1-beta",
                                    "product_id": "CSAFPID-5735971"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.2-beta",
                                "product": {
                                    "name": "vers:unknown/v1.2.2-beta",
                                    "product_id": "CSAFPID-5735972"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.3-beta",
                                "product": {
                                    "name": "vers:unknown/v1.2.3-beta",
                                    "product_id": "CSAFPID-5735973"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.4-beta",
                                "product": {
                                    "name": "vers:unknown/v1.2.4-beta",
                                    "product_id": "CSAFPID-5735974"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.5-beta",
                                "product": {
                                    "name": "vers:unknown/v1.2.5-beta",
                                    "product_id": "CSAFPID-5735975"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.6-beta",
                                "product": {
                                    "name": "vers:unknown/v1.2.6-beta",
                                    "product_id": "CSAFPID-5735976"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.0-beta",
                                "product": {
                                    "name": "vers:unknown/v1.3.0-beta",
                                    "product_id": "CSAFPID-5735977"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.1-beta",
                                "product": {
                                    "name": "vers:unknown/v1.3.1-beta",
                                    "product_id": "CSAFPID-5735978"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.3.2-beta",
                                "product": {
                                    "name": "vers:unknown/v1.3.2-beta",
                                    "product_id": "CSAFPID-5735979"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "sz-boot-parent"
                    }
                ],
                "category": "vendor",
                "name": "feiyuchuixue"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.0-beta",
                                "product": {
                                    "name": "vers:unknown/1.0.0-beta",
                                    "product_id": "CSAFPID-5730934",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.0.0:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.1-beta",
                                "product": {
                                    "name": "vers:unknown/1.0.1-beta",
                                    "product_id": "CSAFPID-5730935",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.0.1:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.2-beta",
                                "product": {
                                    "name": "vers:unknown/1.0.2-beta",
                                    "product_id": "CSAFPID-5730936",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.0.2:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.0-beta",
                                "product": {
                                    "name": "vers:unknown/1.1.0-beta",
                                    "product_id": "CSAFPID-5730937",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.1.0:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.0-beta",
                                "product": {
                                    "name": "vers:unknown/1.2.0-beta",
                                    "product_id": "CSAFPID-5730938",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.2.0:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.1-beta",
                                "product": {
                                    "name": "vers:unknown/1.2.1-beta",
                                    "product_id": "CSAFPID-5730939",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.2.1:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.2-beta",
                                "product": {
                                    "name": "vers:unknown/1.2.2-beta",
                                    "product_id": "CSAFPID-5730940",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.2.2:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.3-beta",
                                "product": {
                                    "name": "vers:unknown/1.2.3-beta",
                                    "product_id": "CSAFPID-5730941",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.2.3:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.4-beta",
                                "product": {
                                    "name": "vers:unknown/1.2.4-beta",
                                    "product_id": "CSAFPID-5730942",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.2.4:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.5-beta",
                                "product": {
                                    "name": "vers:unknown/1.2.5-beta",
                                    "product_id": "CSAFPID-5730943",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.2.5:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.6-beta",
                                "product": {
                                    "name": "vers:unknown/1.2.6-beta",
                                    "product_id": "CSAFPID-5730944",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.2.6:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.0-beta",
                                "product": {
                                    "name": "vers:unknown/1.3.0-beta",
                                    "product_id": "CSAFPID-5730945",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.3.0:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.1-beta",
                                "product": {
                                    "name": "vers:unknown/1.3.1-beta",
                                    "product_id": "CSAFPID-5730946",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.3.1:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.3.2-beta",
                                "product": {
                                    "name": "vers:unknown/1.3.2-beta",
                                    "product_id": "CSAFPID-5730947",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:1.3.2:beta:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=0.9.0",
                                "product": {
                                    "name": "vers:unknown/<=0.9.0",
                                    "product_id": "CSAFPID-5730933",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:szadmin:sz-boot-parent:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "sz-boot-parent"
                    }
                ],
                "category": "vendor",
                "name": "szadmin"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-3185",
            "cwe": {
                "id": "CWE-639",
                "name": "Authorization Bypass Through User-Controlled Key"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the argument messageId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 1.3.3-beta is able to address this issue. The patch is identified as aefaabfd7527188bfba3c8c9eee17c316d094802. The affected component should be upgraded. The project was informed beforehand and acted very professional: \"We have implemented message ownership verification, so that users can only query messages related to themselves.\"",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-3185"
                },
                {
                    "category": "description",
                    "text": "A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the argument messageId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 1.3.3-beta is able to address this issue. The patch is identified as aefaabfd7527188bfba3c8c9eee17c316d094802. The affected component should be upgraded. The project was informed beforehand and acted very professional: \"We have implemented message ownership verification, so that users can only query messages related to themselves.\"",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-3185"
                },
                {
                    "category": "description",
                    "text": "A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the argument messageId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. Upgrading to version 1.3.3-beta is able to address this issue. The patch is identified as aefaabfd7527188bfba3c8c9eee17c316d094802. The affected component should be upgraded. The project was informed beforehand and acted very professional: \"We have implemented message ownership verification, so that users can only query messages related to themselves.\"",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-3185.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00044",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "5.5",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "3.4",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is exploit data available from source Nvd, There is exploit data available from source Cveprojectv5, Exploit code publicly available",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5702101",
                    "CSAFPID-5730933",
                    "CSAFPID-5730934",
                    "CSAFPID-5730935",
                    "CSAFPID-5730936",
                    "CSAFPID-5730937",
                    "CSAFPID-5730938",
                    "CSAFPID-5730939",
                    "CSAFPID-5730940",
                    "CSAFPID-5730941",
                    "CSAFPID-5730942",
                    "CSAFPID-5730943",
                    "CSAFPID-5730944",
                    "CSAFPID-5730945",
                    "CSAFPID-5730946",
                    "CSAFPID-5730947",
                    "CSAFPID-5735939",
                    "CSAFPID-5735940",
                    "CSAFPID-5735941",
                    "CSAFPID-5735942",
                    "CSAFPID-5735943",
                    "CSAFPID-5735944",
                    "CSAFPID-5735945",
                    "CSAFPID-5735946",
                    "CSAFPID-5735947",
                    "CSAFPID-5735948",
                    "CSAFPID-5735949",
                    "CSAFPID-5735950",
                    "CSAFPID-5735951",
                    "CSAFPID-5735952",
                    "CSAFPID-5735953",
                    "CSAFPID-5735954",
                    "CSAFPID-5735955",
                    "CSAFPID-5735956",
                    "CSAFPID-5735957",
                    "CSAFPID-5735958",
                    "CSAFPID-5735959",
                    "CSAFPID-5735960",
                    "CSAFPID-5735961",
                    "CSAFPID-5735962",
                    "CSAFPID-5735963",
                    "CSAFPID-5735964",
                    "CSAFPID-5735965",
                    "CSAFPID-5735966",
                    "CSAFPID-5735967",
                    "CSAFPID-5735968",
                    "CSAFPID-5735969",
                    "CSAFPID-5735970",
                    "CSAFPID-5735971",
                    "CSAFPID-5735972",
                    "CSAFPID-5735973",
                    "CSAFPID-5735974",
                    "CSAFPID-5735975",
                    "CSAFPID-5735976",
                    "CSAFPID-5735977",
                    "CSAFPID-5735978",
                    "CSAFPID-5735979"
                ],
                "known_not_affected": [
                    "CSAFPID-5702552"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3185"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-3185"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-3185"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/3xxx/CVE-2026-3185.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-3185"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-3185.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/feiyuchuixue/sz-boot-parent/"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/feiyuchuixue/sz-boot-parent/commit/aefaabfd7527188bfba3c8c9eee17c316d094802"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/feiyuchuixue/sz-boot-parent/releases/tag/v1.3.3-beta"
                },
                {
                    "category": "external",
                    "summary": "Reference - nvd; osv",
                    "url": "https://github.com/yuccun/CVE/blob/main/sz-boot-parent-IDOR_Message_ID_Enumeration.md"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://vuldb.com/?ctiid.347743"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://vuldb.com/?id.347743"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://vuldb.com/?submit.754036"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-5702101",
                        "CSAFPID-5730933",
                        "CSAFPID-5730934",
                        "CSAFPID-5730935",
                        "CSAFPID-5730936",
                        "CSAFPID-5730937",
                        "CSAFPID-5730938",
                        "CSAFPID-5730939",
                        "CSAFPID-5730940",
                        "CSAFPID-5730941",
                        "CSAFPID-5730942",
                        "CSAFPID-5730943",
                        "CSAFPID-5730944",
                        "CSAFPID-5730945",
                        "CSAFPID-5730946",
                        "CSAFPID-5730947",
                        "CSAFPID-5735939",
                        "CSAFPID-5735940",
                        "CSAFPID-5735941",
                        "CSAFPID-5735942",
                        "CSAFPID-5735943",
                        "CSAFPID-5735944",
                        "CSAFPID-5735945",
                        "CSAFPID-5735946",
                        "CSAFPID-5735947",
                        "CSAFPID-5735948",
                        "CSAFPID-5735949",
                        "CSAFPID-5735950",
                        "CSAFPID-5735951",
                        "CSAFPID-5735952",
                        "CSAFPID-5735953",
                        "CSAFPID-5735954",
                        "CSAFPID-5735955",
                        "CSAFPID-5735956",
                        "CSAFPID-5735957",
                        "CSAFPID-5735958",
                        "CSAFPID-5735959",
                        "CSAFPID-5735960",
                        "CSAFPID-5735961",
                        "CSAFPID-5735962",
                        "CSAFPID-5735963",
                        "CSAFPID-5735964",
                        "CSAFPID-5735965",
                        "CSAFPID-5735966",
                        "CSAFPID-5735967",
                        "CSAFPID-5735968",
                        "CSAFPID-5735969",
                        "CSAFPID-5735970",
                        "CSAFPID-5735971",
                        "CSAFPID-5735972",
                        "CSAFPID-5735973",
                        "CSAFPID-5735974",
                        "CSAFPID-5735975",
                        "CSAFPID-5735976",
                        "CSAFPID-5735977",
                        "CSAFPID-5735978",
                        "CSAFPID-5735979"
                    ]
                }
            ],
            "title": "CVE-2026-3185"
        }
    ]
}