CVE-2026-92753
nicheAuthorization Bypass in PatrowlManager Events and Alerts API
PatrowlManager, an open-source threat-intelligence and security-operations management platform, fails through version 1.8.4 to enforce object-level authorization on its events and alerts API endpoints, which lack ownership filtering (CWE-862). Any attacker with a valid low-privilege account and network access to the instance can call these endpoints to read the platform's full event history, delete arbitrary events, and modify alert records belonging to other users. The flaw requires no user interaction and is scored 7.1 (high) under CVSS 4.0. All deployments running PatrowlManager 1.8.4 or earlier are affected, especially multi-user or internet-exposed instances. No public proof-of-concept is known, the flaw is not in CISA KEV, and no exploitation has been reported.
What to do: Check the Patrowl GitHub project for a patched release beyond 1.8.4 and upgrade as soon as one is available. Until then, restrict access to the PatrowlManager web UI and API to trusted networks via firewall or VPN, limit the number of low-privilege accounts on shared instances, and review logs for unexplained event deletions or alert modifications by non-owner accounts.
| PatrowlManager | all versions through and including 1.8.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.