CVE-2026-40043 Details
Description
Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate privileges by manipulating the original_username cookie. Attackers can set the client-controlled original_username cookie to any value and request a switch to user ID 1 to obtain session tokens or password hashes belonging to administrator accounts.
An authentication bypass vulnerability has been identified in Pachno version 1.0.6, specifically within the runSwitchUser() action. This vulnerability allows authenticated low-privilege users to manipulate the original_username cookie and escalate privileges by switching to user ID 1. Exploiting this flaw enables access to session tokens or password hashes of administrator accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 13, 2026CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.zeroscience.mk/#/advisories/ZSL-2026-5985 | CISA-ADP | |
| https://www.vulncheck.com/advisories/pachno-authentication-bypass-via-runswitchuser | [email protected] | Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5985.php | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Pachno | <= 1.0.6 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | New CVE Received | [email protected] |
Volerion