VYPR
Unrated severityNVD Advisory· Published Jun 10, 2021· Updated Aug 3, 2024

CVE-2021-31927

CVE-2021-31927

Description

An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients. It was fixed in v2021.1.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated attacker can modify any existing user in Annex Cloud Loyalty Experience Platform before 2021.1.0.2 via an Insecure Direct Object Reference (IDOR) vulnerability.

Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability exists in Annex Cloud Loyalty Experience Platform versions prior to 2021.1.0.2 [1][2]. The vulnerability allows any authenticated attacker to modify any existing user, including users assigned to different environments and clients, due to improper access control checks on user modification endpoints [1]. The issue was fixed in version 2021.1.0.2 [1].

Exploitation

An attacker needs to be authenticated to the Annex Cloud Loyalty Experience Platform [1]. Once authenticated, the attacker can craft requests targeting user modification endpoints, directly referencing user identifiers that belong to other environments or clients without proper authorization checks [1]. No additional privileges beyond standard authentication are required to exploit this flaw.

Impact

Successful exploitation allows an authenticated attacker to arbitrarily modify user accounts across different environments and clients within the platform [1]. This can lead to unauthorized privilege escalation, data integrity compromise, and potential lateral movement or account takeover, violating the confidentiality and integrity of user data [1].

Mitigation

The vulnerability is fixed in Annex Cloud Loyalty Experience Platform version 2021.1.0.2 [1]. Organizations using affected versions (prior to 2021.1.0.2) should upgrade immediately to the fixed release [1][2]. No workarounds are documented in the available references [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.