PT-2026-94040 · Patrowl+1 · Patrowlmanager

·

CVE-2026-92754

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PatrowlManager versions prior to 1.8.5
Description Improper access control exists in the user listing API endpoint because the authorization decorator is commented out. This allows authenticated attackers with low-privilege accounts to enumerate all users and their privilege flags, such as superuser and staff status.
Recommendations Update PatrowlManager to version 1.8.5 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92754

Affected Products

Patrowlmanager