AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17601

HIGH · CVSS 8.9 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists that allows users with permission to update privilege definitions to exploit wildcard privileges, enabling them to grant themselves broader permissions, including full administrative access, without proper authorization checks. This poses a significant risk as it can lead to unauthorized access and control over sensitive systems. Organizations with role-based access controls should prioritize addressing this vulnerability to mitigate potential security breaches.

CVE
CVE-2026-17601
Severity
HIGH
CVSS
8.9
EPSS
0.21%

Original NVD Description

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.