Improper Privilege Management in OpenBoxes by OpenBoxes
CVE-2026-19928
Key Information:
Badges
What is CVE-2026-19928?
The vulnerability affects the function needManager in the Role Interceptor component of OpenBoxes, potentially allowing unauthorized users to manipulate access privileges. An attacker could remotely execute an exploit that compromises the intended access control mechanisms of the application, leading to unauthorized actions within the system. It is recommended to upgrade to version 0.9.8-hotfix1 or 0.9.8 to mitigate this risk, as these updates include critical patches to address the identified security flaw.
Affected Version(s)
OpenBoxes 0.9.0
OpenBoxes 0.9.1
OpenBoxes 0.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
