CVE-2026-42185 Details
Description
People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current domain access) to the Owner role. The exploit requires a single authenticated HTTP request and grants full domain ownership immediately, without any acceptance step from the target. This issue has been patched in version 1.25.0.
A privilege escalation vulnerability has been identified in the People application of La Suite Numérique, specifically in version 1.23.1. The issue allows a user with the Administrator role on a mail domain to send a crafted invitation request that promotes any existing user, including those with no current domain access, to the Owner role. This exploitation requires a single authenticated HTTP request and grants immediate full domain ownership, bypassing any acceptance step from the target user.
Users are advised to update to version 1.25.0, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/suitenumerique/people/security/advisories/GHSA-42cf-rv2h-v8rf | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/suitenumerique/people/commit/6a51b96d8e907483fa8fc489d8714cc35fb4099b | [email protected] | Source CodeVendor |
| https://github.com/suitenumerique/people/releases/tag/v1.25.0 | [email protected] | Release NotesVendor |
| https://github.com/suitenumerique/people/security/advisories/GHSA-42cf-rv2h-v8rf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| suitenumerique people | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
| May 8, 2026 | CVE Modified | CISA-ADP |
Volerion