Impact
Squirro Cognitive Search contains a flaw that lets a remote attacker send a crafted request to the service, which can result in privilege escalation. The vulnerability is tied to the platform’s access control logic, allowing an attacker to gain higher-level permissions than intended.
Affected Systems
All instances of Squirro Cognitive Search running a version earlier than 3.14.2 are affected. No other vendors or products are reported to be impacted.
Risk and Exploitability
The CVSS score of 9.8 categorises the flaw as critical. The EPSS score of <1% indicates a very low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalogue. The exploit requires remote network access to the Cognitive Search API, but the documentation does not specify whether authentication is required to trigger the privilege escalation, so the exact scope is unclear.
OpenCVE Enrichment