ZeroHour

CVE-2026-92753

niche

Authorization Bypass in PatrowlManager Events and Alerts API

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

PatrowlManager, an open-source threat-intelligence and security-operations management platform, fails through version 1.8.4 to enforce object-level authorization on its events and alerts API endpoints, which lack ownership filtering (CWE-862). Any attacker with a valid low-privilege account and network access to the instance can call these endpoints to read the platform's full event history, delete arbitrary events, and modify alert records belonging to other users. The flaw requires no user interaction and is scored 7.1 (high) under CVSS 4.0. All deployments running PatrowlManager 1.8.4 or earlier are affected, especially multi-user or internet-exposed instances. No public proof-of-concept is known, the flaw is not in CISA KEV, and no exploitation has been reported.

What to do: Check the Patrowl GitHub project for a patched release beyond 1.8.4 and upgrade as soon as one is available. Until then, restrict access to the PatrowlManager web UI and API to trusted networks via firewall or VPN, limit the number of low-privilege accounts on shared instances, and review logs for unexplained event deletions or alert modifications by non-owner accounts.

Affected
PatrowlManagerall versions through and including 1.8.4
Estimated exposure
nichelikely hundreds to a few thousand self-hosted instances — PatrowlManager is a niche self-hosted open-source SOC/threat-intel platform with a small community footprint and no public install or internet-scan telemetry, so deployments are plausibly in the hundreds to low thousands.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.