CVE-2026-30269

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privilege escalation to high-privileged roles.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:doorman:doorman:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:doorman:doorman:1.0.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-20 17:16

Updated : 2026-06-17 10:32


NVD link : CVE-2026-30269

Mitre link : CVE-2026-30269

CVE.ORG link : CVE-2026-30269


JSON object : View

Products Affected

doorman

  • doorman
CWE
CWE-269

Improper Privilege Management