CVE-2026-8077 Details
Description
Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls, leaving security entirely to the frontend. By modifying the binary string in the ‘Permissions’ field of the JSON response, an attacker could escalate privileges and gain full administrative access. This vulnerability allows all restrictions to be bypassed and completely compromises system management.
A vulnerability in the CashDro 3 web administration panel, version 24.01.00.26, allows for unauthorized privilege escalation. The backend fails to enforce proper authorization, relying solely on frontend controls. By manipulating the 'Permissions' field in the JSON response, an attacker can gain full administrative access, bypassing all restrictions and compromising system management. This issue was discovered during a penetration test at a Spanish leisure center, where the CashDro smart cash management drawer was found to be connected to an internal network accessible via a public-facing port.
Users are advised to update to CashDro 3 version 26.01.00.16, the currently supported version, which includes the necessary authorization controls. Previous versions have been removed from the distribution repository for security reasons.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.itresit.es/2026/05/07/cashdro-vulnerabilities-from-pentest-to-stealing-money/ | CISA-ADP | BundleExploitRemedyTechnical Analysis |
| https://labs.itresit.es/2026/05/07/cashdro-vulnerabilities-from-pentest-to-stealing-money/ | [email protected] | BundleExploitRemedyTechnical Analysis |
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-cashdro-3 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CashDro 3 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion