A vulnerability was found in cedar-policy Authorization for Expressjs up to 0.2.x and classified as problematic. This issue affects some unknown processing. The manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-49473. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.