CVE-2026-92753 Details
Description
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
An authorization bypass vulnerability has been identified in PatrowlManager versions through 1.8.4. This vulnerability exists in the events and alerts API endpoints, which do not implement proper ownership filtering. As a result, authenticated attackers can access the platform's event history, delete any events, and alter alerts that belong to other users.
Users are advised to update to a version of PatrowlManager that includes the necessary ownership checks and authorization validations in the events and alerts API endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Patrowl/PatrowlManager/issues/474 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Patrowl/PatrowlManager | [email protected] | ProductSource CodeVendor |
| https://github.com/Patrowl/PatrowlManager/blob/1.8.4/events/apis.py#L15-L60 | [email protected] | Source CodeVendor |
| https://github.com/Patrowl/PatrowlManager/issues/474 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/patrowlmanager-through-1.8.4-authorization-bypass-via-events-api | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PatrowlManager | <= 1.8.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion