Description
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer settings. An attacker can redirect all SSO logins to an attacker-controlled identity provider, enabling credential harvesting for all platform users.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Peppermint Lab’s Peppermint product permits any authenticated user who is not an administrator to alter the platform’s global OIDC/SSO configuration through an unsecured endpoint. The bug allows this endpoint to change the OIDC issuer without performing an administrative role check, enabling the attacker to redirect all SSO logins to an attacker‑controlled identity provider. If successful, the attacker can harvest credentials for every user that authenticates through the platform, effectively compromising the entire user base. The weakness is a classic broken access control error that facilitates both privilege escalation within the platform and subsequent credential theft.

Affected Systems

The flaw exists in releases of Peppermint that contain the code commit identified as ba6e217. Any deployment running that commit, or any successor version that has not applied the fix, is considered affected. The product in question is Peppermint Lab’s Peppermint platform.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. While EPSS data is not available, the nature of the flaw—requiring only authenticated non‑admin access—suggests that exploitation is relatively straightforward, relying on common credential usage patterns. The vulnerability is not listed in the CISA KEV catalog, but that does not diminish its potential impact, given the ability to intercept all SSO traffic. Attackers could execute this exploit remotely by simply logging in with any valid non‑admin account and sending a configuration request to the vulnerable endpoint.

Generated by OpenCVE AI on August 11, 2026 at 16:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest patched release of Peppermint that contains the fix for the configuration endpoint.
  • Audit the current OIDC/SSO settings and revert any modifications made by non‑administrative users, restoring legitimate issuer values.
  • Enforce strict access control on the configuration endpoint by restricting it to users with administrative roles or by applying network segmentation so that only trusted administrative IP ranges can reach the endpoint.

Generated by OpenCVE AI on August 11, 2026 at 16:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Peppermint
Peppermint peppermint
Vendors & Products Peppermint
Peppermint peppermint

Tue, 11 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer settings. An attacker can redirect all SSO logins to an attacker-controlled identity provider, enabling credential harvesting for all platform users.
Title Peppermint Lab Peppermint - Broken Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Peppermint Peppermint
cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published:

Updated: 2026-08-11T12:18:54.557Z

Reserved: 2026-08-10T10:32:49.082Z

Link: CVE-2026-72561

cve-icon Vulnrichment

Updated: 2026-08-11T12:18:37.468Z

cve-icon NVD

Status : Received

Published: 2026-08-11T12:17:42.073

Modified: 2026-08-11T13:19:03.477

Link: CVE-2026-72561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:45:03Z

Weaknesses