CVE-2026-72564

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 11:17

Updated : 2026-08-28 18:51


NVD link : CVE-2026-72564

Mitre link : CVE-2026-72564

CVE.ORG link : CVE-2026-72564


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key