PT-2026-60506 · Axelor+1 · Axelor-Open-Platform

·

CVE-2026-63085

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axelor Open Platform versions prior to 8.2.2
Description An authorization bypass allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields, specifically roles and group, by submitting changes through a related entity's save path. This process bypasses the USER RESTRICTED FIELDS control, causing the JPA (Java Persistence API) persistence layer to flush attacker-supplied admin role and group assignments upon commit.
Recommendations Update Axelor Open Platform to version 8.2.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63085

Affected Products

Axelor-Open-Platform