AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-36126

HIGH · CVSS 8.1 EPSS 1.40%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-05-07 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2020-36126
Severity
HIGH
CVSS
8.1
EPSS
1.40%

Original NVD Description

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTORE marketplace endpoints allow an authenticated user to read and write data not owned by them, including third-party users, application and payment terminals, where an attacker can impersonate any user which may lead to the unauthorized disclosure, modification, or destruction of information.

Related CVEs

Other vulnerabilities affecting the same vendor(s)