CVE-2026-8077 PUBLISHED

Weak credentials vulnerability in the CashDro 3 web administration panel

Assigner: INCIBE
Reserved: 07.05.2026 Published: 08.05.2026 Updated: 08.05.2026

Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls, leaving security entirely to the frontend. By modifying the binary string in the ‘Permissions’ field of the JSON response, an attacker could escalate privileges and gain full administrative access. This vulnerability allows all restrictions to be bypassed and completely compromises system management.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor CashDro
Product CashDro 3 Administration Panel
Versions Default: unaffected
  • Version 24.01.00.26 is affected

Solutions

The fix has been incorporated into the supported versions of the product. The currently supported version, which is required for the update, is 26.01.00.16. Previous versions have been removed from the distribution repository for security reasons.

Credits

  • Pedro Gabaldón Juliá finder
  • Javier Medina Munuera finder
  • David Montoro Aguilera finder
  • Javier Ayala Ortín finder
  • Pedro Castillo Torío finder

References

Problem Types

  • CWE-862: Missing Authorization CWE