CVE-2026-3209

A vulnerability has been found in fosrl Pangolin up to 1.15.4-s.3. This affects the function verifyRoleAccess/verifyApiKeyRoleAccess of the component Role Handler. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 1.15.4-s.4 mitigates this issue. The identifier of the patch is 5e37c4e85fae68e756be5019a28ca903b161fdd5. Upgrading the affected component is advised.
Configurations

No configuration.

History

08 Mar 2026, 08:15

Type Values Removed Values Added
References
  • () https://vuldb.com/?submit.766215 -

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en fosrl Pangolin hasta 1.15.4-s.3. Esto afecta a la función verifyRoleAccess/verifyApiKeyRoleAccess del componente Gestor de Roles. La manipulación conduce a controles de acceso inadecuados. La explotación remota del ataque es posible. El exploit ha sido revelado al público y puede ser utilizado. Actualizar a la versión 1.15.4-s.4 mitiga este problema. El identificador del parche es 5e37c4e85fae68e756be5019a28ca903b161fdd5. Se aconseja actualizar el componente afectado.

25 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 23:16

Updated : 2026-03-08 08:15


NVD link : CVE-2026-3209

Mitre link : CVE-2026-3209

CVE.ORG link : CVE-2026-3209


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control