Loading market data...
← Back to CVE feed

CVE-2026-92754

MEDIUM CVSS 4.3 View on NVD ↗

Description

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the endpoint.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Sep 16, 2026 21:17 UTC Modified: Sep 17, 2026 14:17 UTC