Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users. | |
| Title | PatrowlManager through 1.8.4 Authorization Bypass via Events API | |
| First Time appeared |
Patrowl
Patrowl patrowlmanager |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:patrowl:patrowlmanager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Patrowl
Patrowl patrowlmanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T18:27:12.268Z
Reserved: 2026-09-16T18:57:08.851Z
Link: CVE-2026-92753
Updated: 2026-09-18T18:27:06.426Z
Status : Deferred
Published: 2026-09-16T21:17:24.180
Modified: 2026-09-23T17:17:49.153
Link: CVE-2026-92753
No data.
OpenCVE Enrichment
Updated: 2026-09-18T07:30:05Z
-
CWE-862
Missing Authorization