PT-2026-60506 · Axelor+1 · Axelor-Open-Platform
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Axelor Open Platform versions prior to 8.2.2
Description
An authorization bypass allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields, specifically
roles and group, by submitting changes through a related entity's save path. This process bypasses the USER RESTRICTED FIELDS control, causing the JPA (Java Persistence API) persistence layer to flush attacker-supplied admin role and group assignments upon commit.Recommendations
Update Axelor Open Platform to version 8.2.2 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Axelor-Open-Platform