CVE-2026-42571 Details
Description
Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). This attack allows any user authenticated to the WebUI via OAuth to gain admin privileges under certain configurations. This issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.
A privilege escalation vulnerability has been identified in Pelican's Web User Interface (WebUI) versions 7.21.0 prior to 7.21.5, 7.22.0 prior to 7.22.3, 7.23.0 prior to 7.23.3, and 7.24.0 prior to 7.24.2. This vulnerability allows users authenticated via OAuth to gain admin privileges under certain configurations. The issue has been patched in versions 7.21.5, 7.22.3, 7.23.3, and 7.24.2.
Users should upgrade to Pelican versions 7.21.5, 7.22.3, 7.23.3, or 7.24.2. If an immediate upgrade is not possible, administrators can disable the vulnerable 'Server.UIAdminUsers' and 'Server.AdminGroups' configurations. For those who have previously used these settings, it's recommended to audit the database for potential exploitation before upgrading.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 9, 2026CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/PelicanPlatform/pelican/commit/7f73b9c3e677a0ae4a0ec465c5d98bb8bd948854 | [email protected] | Source CodeVendor |
| https://github.com/PelicanPlatform/pelican/security/advisories/GHSA-rpfr-x88x-xwcw | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Pelican | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 9, 2026 | New CVE Received | [email protected] |
Volerion