Authorization Flaw in MphRx's Minerva Affects User Privileges
CVE-2026-5781
8.5HIGH
What is CVE-2026-5781?
An authorization vulnerability exists in MphRx's Minerva version 3.6.0, specifically within the '/minerva/moUser/update' endpoint. This flaw allows an authenticated user with user modification privileges to exploit the system by sending a specially crafted HTTP request that manipulates the 'identifier' field. As a result, the attacker could potentially escalate their privileges to that of an administrator, compromising the integrity and security of the application. This vulnerability is particularly concerning as it cannot be exploited through the graphical user interface, highlighting the need for robust security measures and vigilant monitoring of network requests.
Affected Version(s)
Minerva 3.6.0
