CVE-2026-92754
- EPSS 0.25%
- Veröffentlicht 16.09.2026 20:32:26
- Zuletzt bearbeitet 23.09.2026 17:17:49
PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their ...
CVE-2026-92753
- EPSS 0.27%
- Veröffentlicht 16.09.2026 20:32:25
- Zuletzt bearbeitet 23.09.2026 17:17:49
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belo...
- EPSS 1.37%
- Veröffentlicht 14.12.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:52
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/...
CVE-2021-43829
- EPSS 59.25%
- Veröffentlicht 14.12.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:52
PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of ...