Privilege Escalation Vulnerability in Internet2 Grouper
CVE-2026-103470

9.3CRITICAL

Key Information:

Vendor

Internet2

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103470?

A privilege escalation vulnerability exists in Internet2 Grouper prior to version 7.5.1. This flaw allows users with permission to create or edit rules in the User Interface to gain unauthorized access to elevated privileges, potentially compromising system integrity and security. Organizations utilizing affected versions are urged to assess their configurations and update to the latest version to mitigate potential exploitation.

Affected Version(s)

Grouper 5.8.3 <= 5.22.5

Grouper 6.0.0 < 6.4.1

Grouper 7.0.0 < 7.5.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.