GHSA-fpjc-8wg6-ph5jHigh

A user holding a permission to update privilege definitions could modify a wildcard privilege...

Published
August 7, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.

🔗 References (4)