A vulnerability was found in cedar-policy Authorization for Expressjs up to 0.2.x and classified as problematic . This issue affects some unknown processing. The manipulation results in improper authorization. This vulnerability is identified as CVE-2026-49473 . The attack can be executed remotely. There is not any exploit available. It is suggested to upgrade the affected component.