OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103470

CRITICAL · CVSS 9.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

In Internet2 Grouper versions prior to 7.5.1, certain configurations allow users with permission to create or edit rules in the User Interface to escalate their privileges, potentially leading to unauthorized access and control over the system. Organizations utilizing this software, particularly those managing sensitive data or user permissions, should prioritize patching to mitigate the risk of exploitation. Immediate action is recommended for all users of affected versions to safeguard against potential breaches.

CVE
CVE-2026-103470
Severity
CRITICAL
CVSS
9.3
EPSS
0.26%

Original NVD Description

In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.