CVE-2026-92754
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 16, 2026
Vendor
unknown
Description
PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the endpoint.