CVE-2026-17601

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-07 17:17

Updated : 2026-09-01 20:54


NVD link : CVE-2026-17601

Mitre link : CVE-2026-17601

CVE.ORG link : CVE-2026-17601


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization