Description
Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by submitting changes through a related entity's save path, bypassing the USER_RESTRICTED_FIELDS control and causing the JPA persistence layer to flush attacker-supplied admin role and group assignments on commit.
Published: 2026-07-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated non‑administrator user can elevate privileges by exploiting a lack of enforcement on field restrictions during nested relational record persistence. By submitting changes through a related entity’s save pathway, the user can assign administrator roles or alter group memberships on a User record, bypassing the USER_RESTRICTED_FIELDS control and causing the JPA persistence layer to flush attacker‑supplied admin role and group assignments upon commit. This results in the attacker gaining full administrative access to the application with all associated functionality and data.

Affected Systems

Axelor Open Platform versions 8.x prior to 8.2.2 are affected, encompassing all product bundles that ship the 8.x release series from axelor:axelor-open-platform. Any installation running the 8.x code with the nested relational persistence logic in place is at risk if it does not update or otherwise restrict modifications to protected user attributes.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity, whereas the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability requires only an authenticated session, and the flaw can be exercised via the web or API interface that handles nested save operations; the likely attack vector is through crafted nested persistence requests. Despite not being listed in the CISA KEV catalog, the vulnerability is confirmed by multiple publicories and can lead to full administrative control if not remediated. Organizations should treat it as a priority for remediation.

Generated by OpenCVE AI on July 31, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Axelor Open Platform to version 8.2.2 or later, which includes the corrected logic for enforcing restricted fields on nested persistence.
  • Check the vendor’s website or release notes for any newer security updates or patches that address this issue and plan an update accordingly.
  • Actively monitor administrative logs and audit trails for unexpected changes to user roles or group assignments, and investigate any anomalies promptly.

Generated by OpenCVE AI on July 31, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Axelor
Axelor axelor-open-platform
Vendors & Products Axelor
Axelor axelor-open-platform

Fri, 17 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User record fields such as roles and group by submitting changes through a related entity's save path, bypassing the USER_RESTRICTED_FIELDS control and causing the JPA persistence layer to flush attacker-supplied admin role and group assignments on commit.
Title Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational Record Persistence
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Axelor Axelor-open-platform
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-17T18:13:14.938Z

Reserved: 2026-07-15T15:45:44.600Z

Link: CVE-2026-63085

cve-icon Vulnrichment

Updated: 2026-07-16T17:52:58.473Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:00:05Z

Weaknesses