GHSA-qqjf-qhrx-83xxMediumCVSS 4.3

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the endpoint.

🔗 References (6)