View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical TrueBooker Account Takeover Flaw (CVE-2026-16142)

🔓 CVEs & KEV

The following critical vulnerabilities have been disclosed:

  • CVE-2026-16142 — CVSS 9.8 — TrueBooker through 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object References
  • CVE-2026-15826 — CVSS 9.8 — User Profile Builder through 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check