{"id":"CVE-2026-92754","summary":"PatrowlManager through 1.8.4 Improper Access Control via users API","details":"PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the endpoint.","modified":"2026-09-18T03:48:42.993551657Z","published":"2026-09-16T20:32:26.280Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92754.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92754.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92754"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/patrowlmanager-through-1.8.4-improper-access-control-via-users-api"},{"type":"REPORT","url":"https://github.com/Patrowl/PatrowlManager/issues/473"},{"type":"PACKAGE","url":"https://github.com/Patrowl/PatrowlManager"},{"type":"ARTICLE","url":"https://github.com/Patrowl/PatrowlManager/blob/1.8.4/users/apis.py#L29-L39"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/patrowl/patrowlmanager","events":[{"introduced":"0"},{"fixed":"d5f0a23cf8eebd7a393dfa2b73e4274f34891dce"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.8.4"},{"fixed":"1.8.4"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["1.8.3","1.8.2","1.8.1","1.8.0","1.7.9","1.7.8","1.7.7","1.7.6","1.7.5","1.7.4","1.7.3","1.7.2","1.7.0","1.6.28","1.6.27","1.0.6","1.6.26","1.6.25","1.6.24","1.6.23","1.6.21","1.6.19","1.6.18","1.6.17","1.6.16","1.6.15","1.6.14","1.6.13","1.6.12","1.6.11","1.6.10","1.6.9","1.6.7","1.6.6","1.6.4","1.6.3","1.6.2","1.6.1","1.6.0","1.5.5-rc5","1.5.5-rc4","1.5.5-rc3","1.5.5-rc2","1.5.5-rc1","1.5.4-rc4","1.5.4-rc3","1.5.4-rc2","1.5.4-rc1","1.5.3","1.5.2","1.5.1","1.5.0","1.4.8","1.4.6","1.4.5","1.4.4","1.4.3","1.4.2","1.4.1","1.4.0","1.3.7","1.3.6","1.3.5","1.3.4","1.3.1","v1.1.3-beta","1.1.3-beta","v1.1.1","v1.1.0","v1.0.6","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92754.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}