CVE-2026-63102 Details
Description
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not affected.
A privilege escalation vulnerability exists in rConfig Core versions prior to 8.2.8. This vulnerability allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. The absence of proper allowlist validation and admin-level authorization checks in the StoreUserRequest component enables attackers to mass-assign the Admin role, granting access to privileged features. rConfig Pro and Enterprise versions are not affected.
Users can update to rConfig Core version 8.2.8 or later, where this vulnerability has been addressed. Instructions for downloading the latest version are available on the rConfig GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rconfig/rconfig/commit/84822f4051ed97d651b1b4d191c6da2aa8c3c037 | [email protected] | Patch |
| https://github.com/rconfig/rconfig/pull/325 | [email protected] | Issue TrackingPatch |
| https://github.com/rconfig/rconfig/releases/tag/core-8.2.8 | [email protected] | ProductRelease Notes |
| https://www.vulncheck.com/advisories/rconfig-privilege-escalation-via-users-api-role-field | [email protected] | PatchRelease NotesThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rconfig rconfig | < 8.2.8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 19, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | CVE Modified | [email protected] |
| Jul 20, 2026 | New CVE Received | [email protected] |