Description
PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the endpoint.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Insecure User Enumeration and Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

PatrowlManager versions through 1.8.4 allow an attacker who has logged in with a low‑privilege account to call the users listing API and retrieve the full list of users, including their privilege flags such as superuser or staff status. This vulnerability is an improper access control flaw (CWE‑862) that exposes sensitive membership information and could enable attackers to gain insight into privileged accounts. The impact is primarily confidentiality and integrity of account information, not direct system compromise. The vulnerability is limited to authenticated users, yet because the authentication required is only that of a normal user, the barrier to exploitation is low.

Affected Systems

The flaw exists in PatrowlManager, version 1.8.4. Users running this or earlier releases are affected. The product is offered by Patrowl.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score of less than 1 % suggests that exploitation is currently rare or unlikely. The vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely by any authenticated user; the attacker simply performs an HTTP request to the user listing endpoint. Because the decorator that should enforce higher‑privilege checks is commented out, the endpoint accepts any authenticated request. The attack does not require elevated privileges or auxiliary tools, making the attack path straightforward once credentials are obtained.

Generated by OpenCVE AI on September 18, 2026 at 00:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PatrowlManager to a version later than 1.8.4 that restores proper authorization on the users API
  • Apply a patch or configuration change that re‑enables the authorization decorator for the listing endpoint or restricts the endpoint to administrators only
  • Monitor API usage logs for abnormal enumeration activity and enforce rate limits on the users endpoint

Generated by OpenCVE AI on September 18, 2026 at 00:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the endpoint.
Title PatrowlManager through 1.8.4 Improper Access Control via users API
First Time appeared Patrowl
Patrowl patrowlmanager
Weaknesses CWE-862
CPEs cpe:2.3:a:patrowl:patrowlmanager:*:*:*:*:*:*:*:*
Vendors & Products Patrowl
Patrowl patrowlmanager
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Patrowl Patrowlmanager
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:58:20.220Z

Reserved: 2026-09-16T18:57:09.197Z

Link: CVE-2026-92754

cve-icon Vulnrichment

Updated: 2026-09-17T13:57:57.977Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:24.323

Modified: 2026-09-23T17:17:49.173

Link: CVE-2026-92754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses