PT-2026-73074 · Openboxes · Openboxes

·

CVE-2026-19928

·

Published

2026-08-16

·

Updated

2026-08-18

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenBoxes versions prior to 0.9.8-hotfix1
Description Remote manipulation of the needManager() function within the Role Interceptor component (located in grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy) can lead to improper privilege management.
Recommendations Update to version 0.9.8-hotfix1 or 0.9.8. As a temporary mitigation, restrict access to the needManager() function.

Exploit

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19928
GHSA-9RRW-FX2P-P2Q7

Affected Products

Openboxes