An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.Referenceshttps://www.tenable.com/security/tns-2026-22