CVE-2026-72564 PUBLISHED

fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication

Assigner: TuranSec
Reserved: 10.08.2026 Published: 10.08.2026 Updated: 10.08.2026

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS Score: 9.6

Product Status

Vendor fosrl
Product Pangolin
Versions Default: unknown
  • affected from 0 to 1.20.0 (incl.)

Credits

  • Bobur Abdugafforov finder

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE