CVE-2026-92753 PUBLISHED

PatrowlManager through 1.8.4 Authorization Bypass via Events API

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Patrowl
Product PatrowlManager
Versions Default: unaffected
  • affected from 0 to 1.8.4 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Missing Authorization CWE