CVE-2026-63102
Last modified
CVE-2026-63102 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not affected.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rconfig | Rconfig | < 8.2.8 |
References
- https://github.com/rconfig/rconfig/pull/325Issue Tracking, Patch
- https://github.com/rconfig/rconfig/releases/tag/core-8.2.8Product, Release Notes
- https://www.vulncheck.com/advisories/rconfig-privilege-escalation-via-users-api-role-fieldPatch, Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-63102?
How severe is CVE-2026-63102?
How do I fix CVE-2026-63102?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63097Dendrite through 0.13.8 contains an improper access control …5.3
- CVE-2026-63098TheHive through 4.1.24 contains an unauthenticated informati…6.9
- CVE-2026-63099TheHive through 4.1.24 contains a broken object-level author…7.1
- CVE-2026-6310Use after free in Dawn in Google Chrome prior to 147.0.7727.…8.3
- CVE-2026-63100Maybe through 0.6.0 contains a missing authorization vulnera…7.1
- CVE-2026-63101Open Event Server through 1.19.1 contains a missing authenti…8.7
- CVE-2026-63105ReadyEcommerce before 4.5.2 contains a stored cross-site scr…5.4
- CVE-2026-63106ReadyEcommerce before 4.5.2 contains an unauthenticated SQL …9.8
- CVE-2026-63107LimeSurvey through 6.17.10 and 7.0.4 contains a server-side …7.7
- CVE-2026-63108Roo Code through 3.54.0 contains a command injection vulnera…8.8
- CVE-2026-6311Uninitialized Use in Accessibility in Google Chrome on Windo…8.3
- CVE-2026-63117FreeRDP is a free implementation of the Remote Desktop Proto…6.5
Are you affected by CVE-2026-63102?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
