CVE-2026-47366
Last modified
CVE-2026-47366 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
Metrics
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-47366?
How severe is CVE-2026-47366?
How do I fix CVE-2026-47366?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4736Improper Handling of Values vulnerability in No-Chicken Echo…7.3
- CVE-2026-47361In versions of the Datadog Android application prior to v541…6.4
- CVE-2026-47362In versions of the Datadog Android application prior to v554…4.6
- CVE-2026-47363In versions of the Datadog Android application prior to v541…6.3
- CVE-2026-47364In versions of the Datadog Android application prior to v545…6.5
- CVE-2026-47365Argument injection vulnerability in WordPress Toolkit before…9.9
- CVE-2026-47367A malicious actor with access to the network and low privile…9.9
- CVE-2026-47368A malicious actor with access to the network could exploit a…8.6
- CVE-2026-47369A malicious actor with access to the network and low privile…9.9
- CVE-2026-4737Use After Free vulnerability in No-Chicken Echo-Mate (SDK/r…7.3
- CVE-2026-47370A malicious actor with access to the network and low privile…9.9
- CVE-2026-47372Crypt::SaltedHash versions through 0.09 for Perl generate in…9.1
Are you affected by CVE-2026-47366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
