Description
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass allowing authenticated attackers to read, delete, and modify events and alerts belonging to other users
Action: Immediate Patch
AI Analysis

Impact

PatrowlManager versions up to 1.8.4 contain a weakness in the events and alerts API that fails to enforce ownership checks. An authenticated attacker can read the event history of any user, delete arbitrary events, and modify alerts owned by other users. This flaw enables data leakage and tampering within the platform, effectively granting the attacker elevated authority over other accounts.

Affected Systems

The vulnerability affects Patrowl Manager 1.8.4 and earlier releases. It is specifically tied to the events and alerts API endpoints exposed by the application.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests current public exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires a valid authenticated session; an attacker would need legitimate credentials or to gain them through other means. Once authenticated, the attacker can bypass authorization controls and perform actions normally protected by user ownership checks.

Generated by OpenCVE AI on September 18, 2026 at 06:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Patrowl Manager to the latest release that includes the ownership filtering fix (e.g., 1.8.5 or newer).
  • Disable or restrict external access to the events and alerts API until a patch is applied, ensuring only authenticated sessions with appropriate scopes can reach these endpoints.
  • Perform a comprehensive audit of event and alert logs to identify any unauthorized modifications or deletions that may have occurred before the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 06:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
Title PatrowlManager through 1.8.4 Authorization Bypass via Events API
First Time appeared Patrowl
Patrowl patrowlmanager
Weaknesses CWE-862
CPEs cpe:2.3:a:patrowl:patrowlmanager:*:*:*:*:*:*:*:*
Vendors & Products Patrowl
Patrowl patrowlmanager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Patrowl Patrowlmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T18:27:12.268Z

Reserved: 2026-09-16T18:57:08.851Z

Link: CVE-2026-92753

cve-icon Vulnrichment

Updated: 2026-09-18T18:27:06.426Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:24.180

Modified: 2026-09-23T17:17:49.153

Link: CVE-2026-92753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses