Privilege Escalation Vulnerability in Internet2 Grouper
CVE-2026-103470
9.3CRITICAL
What is CVE-2026-103470?
A privilege escalation vulnerability exists in Internet2 Grouper prior to version 7.5.1. This flaw allows users with permission to create or edit rules in the User Interface to gain unauthorized access to elevated privileges, potentially compromising system integrity and security. Organizations utilizing affected versions are urged to assess their configurations and update to the latest version to mitigate potential exploitation.
Affected Version(s)
Grouper 5.8.3 <= 5.22.5
Grouper 6.0.0 < 6.4.1
Grouper 7.0.0 < 7.5.1
