PT-2026-70130 · Pepperminty · Peppermint

·

CVE-2026-72555

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Peppermint Lab Peppermint versions through commit ba6e217
Description Broken access control occurs because the Config.roles active flag defaults to false, which causes permission checks on ticket, client, and user handlers to behave as no-ops (operations that have no effect) on default installations. Consequently, all authenticated users can bypass ownership and administrative access controls, allowing an attacker with any user account to read, modify, or delete tickets, clients, and users belonging to other accounts.
Recommendations Update Peppermint Lab Peppermint to a version beyond commit ba6e217. Enable the Config.roles active flag to ensure permission checks are active.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72555

Affected Products

Peppermint