A vulnerability, which was classified as problematic, was found in duck-organization questbot up to 1.1.5. Affected by this vulnerability is an unknown functionality. Such manipulation leads to incorrect authorization.
This vulnerability is listed as CVE-2026-47195. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.