Vulnerability Description
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Patrowl/PatrowlManager
- https://github.com/Patrowl/PatrowlManager/blob/1.8.4/events/apis.py#L15-L60
- https://github.com/Patrowl/PatrowlManager/issues/474
- https://www.vulncheck.com/advisories/patrowlmanager-through-1.8.4-authorization-
- https://github.com/Patrowl/PatrowlManager/issues/474
FAQ
What is CVE-2026-92753?
CVE-2026-92753 is a vulnerability with a CVSS score of 7.1 (HIGH). PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event histor...
How severe is CVE-2026-92753?
CVE-2026-92753 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-92753?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.