A vulnerability classified as critical was found in kvf-admin 1.0.0. Impacted is an unknown function of the file UserController.java. The manipulation results in permission issues.
This vulnerability is reported as CVE-2026-38807. The attack can be launched remotely. No exploit exists.